CVE-2026-63947
Linux Bluetooth HIDP bug permits phantom input or DoS via truncated packets
Is CVE-2026-63947 being exploited?
Not confirmed. CVE-2026-63947 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.34% probability of exploitation in the next 30 days.
How severe is CVE-2026-63947?
CVE-2026-63947 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63947?
Yes. A fix has been recorded for CVE-2026-63947. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63947 affect?
CVE-2026-63947 affects Linux kernel (Bluetooth HIDP subsystem), Linux desktops/laptops with Bluetooth HID, Embedded/Linux IoT devices with HIDP-enabled kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63947?
Apply kernel update that fixes HIDP length checks; disable/unpair Bluetooth HID if patching delayed
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A paired Bluetooth device can send crafted truncated HID packets causing out-of-bounds reads that produce phantom keystrokes/mouse events or crash the kernel (DoS).
Patch when possible
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 1f08a90013e1e632b34321334e861fcefc056505
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < cc3832b19f863e3677c5651f001a2e3795f39eb8
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < d313683d6ccdd8c01e0562270a2ae25b86d8461d
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < d7d6a81b8dd1a8d084a1b755db9406041d53adb5
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 6348dfed5b0f9c6074f14322332e97493d32fef0
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < b83dcacd2ec7fcc5a48be215f82d573759f87ec2
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.