PT-2026-104971 · Azure Linux · Kernel
Publicado
2026-09-24
·
Atualizado
2026-09-24
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: validate skb length in rfcomm recv frame
rfcomm recv frame() casts skb->data to struct rfcomm hdr and dereferences
hdr->addr and hdr->ctrl without validating skb->len first. A truncated
frame with skb->len less than the minimum header size causes an
out-of-bounds read of uninitialized memory. Additionally, a zero-length
frame causes skb->len-- to underflow to UINT MAX, making
skb tail pointer() read far past the buffer.
Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC
handlers") fixed the same class of missing-length-check bugs in the MCC
sub-handlers, but the top-level rfcomm recv frame() was left unfixed.
KMSAN reports:
BUG: KMSAN: uninit-value in rfcomm run
...
Uninit was created at:
alloc skb+0x474/0xb60
vhci write+0xe9/0x870
Fix this by rejecting frames smaller than sizeof(struct rfcomm hdr) + 1
(the minimum frame must have a 3-byte header and a 1-byte FCS).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel