« Volver al listado

CVE-2026-64403

Estado: AnalizadaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: validate option length before reading conf opt value

l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately dereferences opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a raw pointer for the default case) before any caller has confirmed that opt->len bytes are present in the buffer. The callers (l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and l2cap_conf_rfc_get()) only detect a malformed option afterwards, once the running length has gone negative, by which point the out-of-bounds read has already executed.

Leer descripción completaMostrar menos

An existing post-hoc length check keeps the garbage value from being consumed, so this is not a data leak in the current control flow. It is still a validate-after-use ordering bug: up to 4 bytes are read past the end of the buffer before it is known to contain them, and it is fragile to future changes in the callers.

Fix it at the source. Pass the end of the buffer into l2cap_get_conf_opt() and refuse to touch opt->val unless the full option (header + value) fits. Each caller computes an end pointer once before the loop and checks the return value directly instead of inferring the error from a negative length.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente) sin privilegios sugiere T1210. La vulnerabilidad es un out-of-bounds read en Bluetooth L2CAP que permite lectura de memoria y DoS por crash del kernel (A:H); no ejecuta código sino que causa negación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64403",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "cca81b4bc672604a84f6d224a55cc77ec7dee619",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "7d871e969b941ce25653f7716203a0ea4d07ad4b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "98d93c226bdfaa79bbdd86981921d7f106374225",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "996d3da39899aceb8f4910911a3f19a45a7d9d1b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "73abbaf91aa33da87c008fb62c148ade561bb606",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "6b47bdaacfd0045687880177e0987055d8f4765a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
              "lessThan": "687617555cedfb74c9e3cb85d759b908dcb17856",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "78c2887130f1a7d1883195732be1b6cdab667487",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ac7c597c465eb09391e40febbe088bdad601080b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ade4560e4fea198866e033fe1c02f063d6d7db2e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99665dcf6ff803351b5e658f3a929cb498561e36",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b59d36f22622c92c0b06aee7571f0a86a217188",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "15d6538a0d6e0f6de5116081a948cba7cc3e1d3d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a556547bae00528f24b42786b41a14047db14b84",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3.16.66",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.18.138",
              "lessThan": "3.19",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.4.178",
              "lessThan": "4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.9.167",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.110",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.33",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.0.6",
              "lessThan": "5.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:23.850",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt->len field and immediately dereferences\nopt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt->len bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt->val unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the loop and checks the return value directly instead of\ninferring the error from a negative length."
    }
  ],
  "lastModified": "2026-09-04T14:45:32.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAFB90C8-E6AC-40FC-B718-C6569511F43B",
              "versionEndExcluding": "3.17",
              "versionStartIncluding": "3.16.66"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F833EC2A-D0F3-4B78-ACB8-05D2EF98BAC3",
              "versionEndExcluding": "3.19",
              "versionStartIncluding": "3.18.138"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A722E651-3556-4E10-9B6A-7D0CE8D0C5D7",
              "versionEndExcluding": "4.5",
              "versionStartIncluding": "4.4.178"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A810207-8023-4209-95E1-F4608AD30BC2",
              "versionEndExcluding": "4.10",
              "versionStartIncluding": "4.9.167"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D307FAA-524F-4DDE-A789-61E8ACCBCB69",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "4.14.110"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C615A8F-45B4-4CC3-9024-95838A7048AC",
              "versionEndExcluding": "4.20",
              "versionStartIncluding": "4.19.33"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67AA953F-BE56-4173-9237-969D0FAF963B",
              "versionEndExcluding": "5.10.261",
              "versionStartIncluding": "5.0.6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E99FB01-CD93-41AF-A653-3F450652B9A6",
              "versionEndExcluding": "5.15.212",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "092233C7-F4E0-40C8-BD4D-A28FE50DFE20",
              "versionEndExcluding": "6.1.178",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7046B092-F810-4440-ACE6-60218518EECE",
              "versionEndExcluding": "6.6.145",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
              "versionEndExcluding": "6.12.96",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
              "versionEndExcluding": "6.18.39",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
              "versionEndExcluding": "7.1.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E8B9085-7ADB-4A05-89EF-12949B6A0509"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FC0D50D-9D58-4947-A197-A5A3FF07E7E3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}