PT-2026-98770 · Linux · Linux
CVE-2026-98108
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
CVSS v3.1
7.5
Alta
| Vetor | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix chan mode for LE CONN REQ + EXT FLOWCTL pchan
l2cap new connection() sets default value of channel mode to match the
parent channel. l2cap le connect req() left this at the default, and
created L2CAP MODE EXT FLOWCTL channels if listening pchan has that
mode. This causes FLAG DEFER SETUP channels to reply to
L2CAP LE CONN REQ with L2CAP ECRED CONN RSP, which is incorrect.
It can also result to stack OOB write (of l2cap alloc cid determined
values) in l2cap ecred rsp defer(), as l2cap le connect req() does not
limit maximum number of deferred channels or check for duplicate ident.
Fix by setting chan->mode correctly in l2cap le connect req().
Also check channel mode in l2cap ecred rsp defer(), and do WARN ON ONCE
instead of OOB write to make it less brittle.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux