PT-2026-98770 · Linux · Linux

CVE-2026-98108

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.5

Alta

VetorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix chan mode for LE CONN REQ + EXT FLOWCTL pchan
l2cap new connection() sets default value of channel mode to match the parent channel. l2cap le connect req() left this at the default, and created L2CAP MODE EXT FLOWCTL channels if listening pchan has that mode. This causes FLAG DEFER SETUP channels to reply to L2CAP LE CONN REQ with L2CAP ECRED CONN RSP, which is incorrect.
It can also result to stack OOB write (of l2cap alloc cid determined values) in l2cap ecred rsp defer(), as l2cap le connect req() does not limit maximum number of deferred channels or check for duplicate ident.
Fix by setting chan->mode correctly in l2cap le connect req().
Also check channel mode in l2cap ecred rsp defer(), and do WARN ON ONCE instead of OOB write to make it less brittle.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98108

Produtos afetados

Linux