CVE-2026-64403
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: validate option length before reading conf opt value
l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately dereferences opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a raw pointer for the default case) before any caller has confirmed that opt->len bytes are present in the buffer. The callers (l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and l2cap_conf_rfc_get()) only detect a malformed option afterwards, once the running length has gone negative, by which point the out-of-bounds read has already executed.
Leer descripción completaMostrar menos
An existing post-hoc length check keeps the garbage value from being consumed, so this is not a data leak in the current control flow. It is still a validate-after-use ordering bug: up to 4 bytes are read past the end of the buffer before it is known to contain them, and it is fragile to future changes in the callers.
Fix it at the source. Pass the end of the buffer into l2cap_get_conf_opt() and refuse to touch opt->val unless the full option (header + value) fits. Each caller computes an end pointer once before the loop and checks the return value directly instead of inferring the error from a negative length.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement45 % - Impacto principal
T1499.004Application or System Exploitationimpact65 %
AV:A (red adyacente) sin privilegios sugiere T1210. La vulnerabilidad es un out-of-bounds read en Bluetooth L2CAP que permite lectura de memoria y DoS por crash del kernel (A:H); no ejecuta código sino que causa negación de servicio.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856
- https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a
- https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606
- https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b
- https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225
- https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b
- https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619
- https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64403",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "cca81b4bc672604a84f6d224a55cc77ec7dee619",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "7d871e969b941ce25653f7716203a0ea4d07ad4b",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "98d93c226bdfaa79bbdd86981921d7f106374225",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "996d3da39899aceb8f4910911a3f19a45a7d9d1b",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "73abbaf91aa33da87c008fb62c148ade561bb606",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "6b47bdaacfd0045687880177e0987055d8f4765a",
"versionType": "git"
},
{
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"lessThan": "687617555cedfb74c9e3cb85d759b908dcb17856",
"versionType": "git"
},
{
"status": "affected",
"version": "78c2887130f1a7d1883195732be1b6cdab667487",
"versionType": "git"
},
{
"status": "affected",
"version": "ac7c597c465eb09391e40febbe088bdad601080b",
"versionType": "git"
},
{
"status": "affected",
"version": "ade4560e4fea198866e033fe1c02f063d6d7db2e",
"versionType": "git"
},
{
"status": "affected",
"version": "99665dcf6ff803351b5e658f3a929cb498561e36",
"versionType": "git"
},
{
"status": "affected",
"version": "2b59d36f22622c92c0b06aee7571f0a86a217188",
"versionType": "git"
},
{
"status": "affected",
"version": "15d6538a0d6e0f6de5116081a948cba7cc3e1d3d",
"versionType": "git"
},
{
"status": "affected",
"version": "a556547bae00528f24b42786b41a14047db14b84",
"versionType": "git"
},
{
"status": "affected",
"version": "3.16.66",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.18.138",
"lessThan": "3.19",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.4.178",
"lessThan": "4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.9.167",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.110",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.33",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.0.6",
"lessThan": "5.1",
"versionType": "semver"
}
],
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:23.850",
"references": [
{
"url": "https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt->len field and immediately dereferences\nopt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt->len bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt->val unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the loop and checks the return value directly instead of\ninferring the error from a negative length."
}
],
"lastModified": "2026-09-04T14:45:32.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAFB90C8-E6AC-40FC-B718-C6569511F43B",
"versionEndExcluding": "3.17",
"versionStartIncluding": "3.16.66"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F833EC2A-D0F3-4B78-ACB8-05D2EF98BAC3",
"versionEndExcluding": "3.19",
"versionStartIncluding": "3.18.138"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A722E651-3556-4E10-9B6A-7D0CE8D0C5D7",
"versionEndExcluding": "4.5",
"versionStartIncluding": "4.4.178"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A810207-8023-4209-95E1-F4608AD30BC2",
"versionEndExcluding": "4.10",
"versionStartIncluding": "4.9.167"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D307FAA-524F-4DDE-A789-61E8ACCBCB69",
"versionEndExcluding": "4.15",
"versionStartIncluding": "4.14.110"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C615A8F-45B4-4CC3-9024-95838A7048AC",
"versionEndExcluding": "4.20",
"versionStartIncluding": "4.19.33"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67AA953F-BE56-4173-9237-969D0FAF963B",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.0.6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E99FB01-CD93-41AF-A653-3F450652B9A6",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "092233C7-F4E0-40C8-BD4D-A28FE50DFE20",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7046B092-F810-4440-ACE6-60218518EECE",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E8B9085-7ADB-4A05-89EF-12949B6A0509"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FC0D50D-9D58-4947-A197-A5A3FF07E7E3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}