CVE-2026-31393
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that the payload is present:
A truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an out-of-bounds read of adjacent skb data.
Guard each data access with the required payload length check. If the payload is too short, skip the read and let the state machine complete with safe defaults (feat_mask and remote_fixed_chan remain zero from kzalloc), so the info timer cleanup and l2cap_conn_start() still run and the connection is not stalled.
Detalles técnicos trazas, registros y código del informe original
- L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads 4 bytes past the header (needs cmd_len >= 8). - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header (needs cmd_len >= 5).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement65 % - Impacto principal
T1005Data from Local Systemcollection75 %
Vulnerabilidad de lectura fuera de límites (CWE-125) en protocolo Bluetooth L2CAP accesible desde red adyacente (AV:A), sin privilegios ni interacción. Impacto de confidencialidad alta (C:H) por acceso a datos en memoria del kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- https://git.kernel.org/stable/c/187e6fe939295be36063a1d91f8bebee04399a8c
- https://git.kernel.org/stable/c/3b646516cba2ebc4b51a72954903326e7c1e443f
- https://git.kernel.org/stable/c/5229e7d15771eac2b5886bfb1f976aea0c1eec14
- https://git.kernel.org/stable/c/807bd1258453c4c83f6ae9dbc1e7b44860ff40d0
- https://git.kernel.org/stable/c/9aeacde4da0f02d42fd968fd32f245828b230171
- https://git.kernel.org/stable/c/db2872d054e467810078e2b9f440a5b326a601b2
- https://git.kernel.org/stable/c/dd815e6e3918dc75a49aaabac36e4f024d675101
- https://git.kernel.org/stable/c/e7ff754e339e3d5ce29aa9f95352d0186df8fbd9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-31393",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "187e6fe939295be36063a1d91f8bebee04399a8c",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "5229e7d15771eac2b5886bfb1f976aea0c1eec14",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "3b646516cba2ebc4b51a72954903326e7c1e443f",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "807bd1258453c4c83f6ae9dbc1e7b44860ff40d0",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "9aeacde4da0f02d42fd968fd32f245828b230171",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "e7ff754e339e3d5ce29aa9f95352d0186df8fbd9",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "db2872d054e467810078e2b9f440a5b326a601b2",
"versionType": "git"
},
{
"status": "affected",
"version": "4e8402a3f884427f9233ba436459c158d1f2e114",
"lessThan": "dd815e6e3918dc75a49aaabac36e4f024d675101",
"versionType": "git"
}
],
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.24",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-04-03T16:16:37.420",
"references": [
{
"url": "https://git.kernel.org/stable/c/187e6fe939295be36063a1d91f8bebee04399a8c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3b646516cba2ebc4b51a72954903326e7c1e443f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5229e7d15771eac2b5886bfb1f976aea0c1eec14",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/807bd1258453c4c83f6ae9dbc1e7b44860ff40d0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9aeacde4da0f02d42fd968fd32f245828b230171",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/db2872d054e467810078e2b9f440a5b326a601b2",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dd815e6e3918dc75a49aaabac36e4f024d675101",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e7ff754e339e3d5ce29aa9f95352d0186df8fbd9",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n 4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header\n (needs cmd_len >= 5).\n\nA truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an\nout-of-bounds read of adjacent skb data.\n\nGuard each data access with the required payload length check. If the\npayload is too short, skip the read and let the state machine complete\nwith safe defaults (feat_mask and remote_fixed_chan remain zero from\nkzalloc), so the info timer cleanup and l2cap_conn_start() still run\nand the connection is not stalled."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nBluetooth: L2CAP: Validar la longitud de la carga útil de L2CAP_INFO_RSP antes del acceso\n\nl2cap_information_rsp() comprueba que cmd_len cubre la cabecera fija de l2cap_info_rsp (tipo + resultado, 4 bytes) pero luego lee rsp -> data sin verificar que la carga útil esté presente:\n\n - L2CAP_IT_FEAT_MASK llama a get_unaligned_le32(rsp -> data), que lee 4 bytes después de la cabecera (necesita cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN lee rsp -> data[0], 1 byte después de la cabecera (necesita cmd_len >= 5).\n\nUn L2CAP_INFO_RSP truncado con result == L2CAP_IR_SUCCESS desencadena una lectura fuera de límites de datos skb adyacentes.\n\nProteger cada acceso a datos con la comprobación de longitud de carga útil requerida. Si la carga útil es demasiado corta, omitir la lectura y permitir que la máquina de estados se complete con valores predeterminados seguros (feat_mask y remote_fixed_chan permanecen en cero desde kzalloc), para que la limpieza del temporizador de información y l2cap_conn_start() sigan ejecutándose y la conexión no se estanque."
}
],
"lastModified": "2026-07-24T22:10:00.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23F88A56-E27D-46A7-B32C-65333C046B72",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "2.6.24"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20DDB3E9-AABF-4107-ADB0-5362AA067045",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EDC6BAF-B710-4E26-B6AA-D68922EE7B43",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C57BB918-DF28-46B3-94F7-144176841267",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28D591F5-B196-4CC9-905C-DC80F116E7A8",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5571059-6552-48E7-9BEF-3E358C387171",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D34333-38BE-4414-9E79-6EB764329581",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}