PT-2026-98769 · Linux · Linux

CVE-2026-98107

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix out-of-bounds write in l2cap ecred connect
l2cap chan connect() tries to ensure there are no more than L2CAP ECRED CONN SCID MAX pending ECRED channels, so they fit in the same L2CAP ECRED CONN REQ that l2cap ecred connect() constructs.
However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one le16 written out of bounds of the scid array, and an invalid ECRED CONN REQ being sent.
Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap chan connect(), so the limit can't be exceeded.
Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see.
Also add WARN ON ONCE check in l2cap ecred defer connect() to make this less brittle.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98107

Affected Products

Linux