OVERVIEW CVE-2026-31497 is a buffer index validation vulnerability in the Linux kernel's Bluetooth USB driver (btusb). The vulnerability exists in the btusb_work() function, which maps active SCO (Synchronous Connection-Oriented) links to USB alternate settings without properly validating the lookup table index. When processing CVSD traffic with transparent voice settings, the driver uses the SCO link count directly as a table index without constraining it to the three available entries, potentially causing out-of-bounds table access. SEVERITY The vulnerability carries a low to moderate risk profile with a CVSS score not yet assigned and an EPSS score of 0.00024, indicating minimal exploitation likelihood. The defect involves direct memory access without bounds checking on the Bluetooth subsystem, which typically requires local system access or a connected Bluetooth device to exploit. The impact is constrained by the three-entry lookup table limitation and the specific conditions required to trigger excessive SCO link counts, reducing both attack complexity and practical exploitability. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active real-world exploitation. No public exploit code is documented, and community attention remains limited given the low EPSS score and specific technical requirements for triggering the flaw. The fix has been implemented in the Linux kernel repository through index clamping, making exploitation unlikely in patched systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.8.1, < 5.10.253CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.203CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.168CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.131CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.80CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure FIPS) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (AWS) vulnerabilities
Jul 24, 2026Linux kernel (NVIDIA) vulnerabilities
Jul 23, 2026Linux kernel (Oracle) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 23, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 21, 2026Linux kernel (GCP FIPS) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 20, 2026Bluetooth: btusb: clamp SCO altsetting table indices
Apr 14, 2026