PT-2026-104971 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: validate skb length in rfcomm recv frame
rfcomm recv frame() casts skb->data to struct rfcomm hdr and dereferences hdr->addr and hdr->ctrl without validating skb->len first. A truncated frame with skb->len less than the minimum header size causes an out-of-bounds read of uninitialized memory. Additionally, a zero-length frame causes skb->len-- to underflow to UINT MAX, making skb tail pointer() read far past the buffer.
Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC handlers") fixed the same class of missing-length-check bugs in the MCC sub-handlers, but the top-level rfcomm recv frame() was left unfixed. KMSAN reports:
BUG: KMSAN: uninit-value in rfcomm run ... Uninit was created at: alloc skb+0x474/0xb60 vhci write+0xe9/0x870
Fix this by rejecting frames smaller than sizeof(struct rfcomm hdr) + 1 (the minimum frame must have a 3-byte header and a 1-byte FCS).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103928

Affected Products

Kernel