PT-2026-98769 · Linux · Linux

CVE-2026-98107

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix out-of-bounds write in l2cap ecred connect
l2cap chan connect() tries to ensure there are no more than L2CAP ECRED CONN SCID MAX pending ECRED channels, so they fit in the same L2CAP ECRED CONN REQ that l2cap ecred connect() constructs.
However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one le16 written out of bounds of the scid array, and an invalid ECRED CONN REQ being sent.
Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap chan connect(), so the limit can't be exceeded.
Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see.
Also add WARN ON ONCE check in l2cap ecred defer connect() to make this less brittle.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98107

Produtos afetados

Linux