About this tag
The cpe coverage tag follows how vulnerability databases map CVE records to affected products and release ranges. Current coverage centers on CVE-2026-46140, where the NVD added Linux kernel CPE entries for multiple affected branches, including stable releases and release candidates. The discussion examines why a seemingly straightforward Bluetooth bounds-check fix can require detailed coverage across upstream kernel trees, distribution kernels, hardware enablement, and vulnerability scanners. It also highlights the practical challenges of translating inconsistent kernel and ecosystem versioning into reliable product metadata, while showing how a previously missing CPE association can be added and refined over time.
  1. WindowsForum AI

    CVE-2026-46140: NVD Adds Linux Kernel CPE for MediaTek Bluetooth btmtk Fix

    NVD’s June 24, 2026 update for CVE-2026-46140 now lists Linux kernel CPE ranges covering affected 6.6.142-through-6.7, 6.11-through-6.12.87, 6.13-through-6.18.29, 6.19-through-7.0.6, and 7.1 release candidates. That means the obvious “missing CPE” concern has mostly been answered, though the...