CVE-2026-98247
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_codec: validate vendor codec count length
The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/12a82819b0cada6e304790b1097f8f9006eb6123
- https://git.kernel.org/stable/c/9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8
- https://git.kernel.org/stable/c/a6da782fefae611e68a1aa79644065fc8ca5abcd
- https://git.kernel.org/stable/c/d0795cfd6f655f4de84868a4f4bb41a03f037b3d
- https://git.kernel.org/stable/c/e4cfd3c4299105237458b27958bd7b0aa4c60795
- https://git.kernel.org/stable/c/f49a543d76d48f184b34225d9c0e2fc4cbdea8ec
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98247",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8",
"versionType": "git"
},
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "a6da782fefae611e68a1aa79644065fc8ca5abcd",
"versionType": "git"
},
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "e4cfd3c4299105237458b27958bd7b0aa4c60795",
"versionType": "git"
},
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "f49a543d76d48f184b34225d9c0e2fc4cbdea8ec",
"versionType": "git"
},
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "12a82819b0cada6e304790b1097f8f9006eb6123",
"versionType": "git"
},
{
"status": "affected",
"version": "8961987f3f5fa2f2618e72304d013c8dd5e604a6",
"lessThan": "d0795cfd6f655f4de84868a4f4bb41a03f037b3d",
"versionType": "git"
}
],
"programFiles": [
"net/bluetooth/hci_codec.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/bluetooth/hci_codec.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:12.940",
"references": [
{
"url": "https://git.kernel.org/stable/c/12a82819b0cada6e304790b1097f8f9006eb6123",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a6da782fefae611e68a1aa79644065fc8ca5abcd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d0795cfd6f655f4de84868a4f4bb41a03f037b3d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e4cfd3c4299105237458b27958bd7b0aa4c60795",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f49a543d76d48f184b34225d9c0e2fc4cbdea8ec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the vendor codec count. Although the\ninitial reply-size check includes a vendor count byte in the fixed layout,\nit does not guarantee that the byte remains after the standard codec array.\n\nIf a controller reply ends immediately after that array, calculating the\nvendor codec array size reads vnd_codecs->num beyond the skb data. Use\nskb_pull_data() to validate and consume each codec header before using its\ncount in both command variants."
}
],
"lastModified": "2026-10-06T09:18:12.940",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}