-

CVE-2026-97408

Bluetooth: L2CAP: validate connectionless PSM length

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: validate connectionless PSM length

Connectionless L2CAP frames carry a two-byte PSM at the start of the
payload.  l2cap_recv_frame() currently reads that PSM unconditionally
after validating only the outer L2CAP length.

A malformed connectionless frame with a zero- or one-byte payload can
therefore make the parser read beyond the advertised skb payload and use
tailroom bytes as part of the PSM.  A VHCI-backed QEMU reproducer
injected a one-byte connectionless payload and reached the unchecked
read.

Reject connectionless frames that cannot contain the PSM before reading
or pulling it.  This preserves all valid connectionless frames while
dropping only structurally incomplete packets.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 8104cd9859b6de0826cffa68adf2c1461185823b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 9448e6f693fcf1f0ac4ee648a9b2cc83bfe4a982
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 22fc1ce4e37c81d4e7aac01566ebdc232214540d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 72e26293a231f63a856340d3a1f0f5fc29bf87e5
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 3502ede8aed3c3ee1786d952a11054ac737d1a38
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < ae69dca122f6d6046a68cf40153e6e827c77ff5c
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < a40a5f922546b3bd7c094d882b29177db4f2abe0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3502ede8aed3c3ee1786d952a11054ac737d1a38
https://git.kernel.org/stable/c/ae69dca122f6d6046a68cf40153e6e827c77ff5c
https://git.kernel.org/stable/c/a40a5f922546b3bd7c094d882b29177db4f2abe0
https://git.kernel.org/stable/c/22fc1ce4e37c81d4e7aac01566ebdc232214540d
https://git.kernel.org/stable/c/72e26293a231f63a856340d3a1f0f5fc29bf87e5
https://git.kernel.org/stable/c/8104cd9859b6de0826cffa68adf2c1461185823b
https://git.kernel.org/stable/c/9448e6f693fcf1f0ac4ee648a9b2cc83bfe4a982