PT-2026-98769 · Linux · Linux
CVE-2026-98107
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix out-of-bounds write in l2cap ecred connect
l2cap chan connect() tries to ensure there are no more than
L2CAP ECRED CONN SCID MAX pending ECRED channels, so they fit in the
same L2CAP ECRED CONN REQ that l2cap ecred connect() constructs.
However, the check only counts deferred channels. If 6 L2CAP sockets
are connected at the same time in order DDDDND (D=deferred,
N=non-deferred), the last can bump the total to max+1. It results to
one le16 written out of bounds of the scid array, and an invalid
ECRED CONN REQ being sent.
Fix by leaving room for the non-deferred pending ECRED channels in the
counting in l2cap chan connect(), so the limit can't be exceeded.
Move counting under same critical section where the channel is added.
Although race conditions involving this appear unreachable, it's easier
to see.
Also add WARN ON ONCE check in l2cap ecred defer connect() to make this
less brittle.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux