« Volver al listado

CVE-2026-98107

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect

l2cap_chan_connect() tries to ensure there are no more than L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the same L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs.

However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one __le16 written out of bounds of the scid array, and an invalid ECRED_CONN_REQ being sent.

Leer descripción completaMostrar menos

Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap_chan_connect(), so the limit can't be exceeded.

Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see.

Also add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this less brittle.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98107",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "da49b602f7f75ccc91386e1274b3ef71676cd092",
              "lessThan": "ce0927eb3ee2939fab5ce3f9334bfd2fafb38481",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "da49b602f7f75ccc91386e1274b3ef71676cd092",
              "lessThan": "6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "da49b602f7f75ccc91386e1274b3ef71676cd092",
              "lessThan": "df8c3af6132640da4788e96a02d653e642059803",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "da49b602f7f75ccc91386e1274b3ef71676cd092",
              "lessThan": "56c2b5831d39dc84aad2573dc3e197af1a872a05",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:41.743",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/56c2b5831d39dc84aad2573dc3e197af1a872a05",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ce0927eb3ee2939fab5ce3f9334bfd2fafb38481",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/df8c3af6132640da4788e96a02d653e642059803",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect\n\nl2cap_chan_connect() tries to ensure there are no more than\nL2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the\nsame L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs.\n\nHowever, the check only counts deferred channels.  If 6 L2CAP sockets\nare connected at the same time in order DDDDND (D=deferred,\nN=non-deferred), the last can bump the total to max+1.  It results to\none __le16 written out of bounds of the scid array, and an invalid\nECRED_CONN_REQ being sent.\n\nFix by leaving room for the non-deferred pending ECRED channels in the\ncounting in l2cap_chan_connect(), so the limit can't be exceeded.\n\nMove counting under same critical section where the channel is added.\nAlthough race conditions involving this appear unreachable, it's easier\nto see.\n\nAlso add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this\nless brittle."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}