-

CVE-2026-98107

Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect

l2cap_chan_connect() tries to ensure there are no more than
L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the
same L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs.

However, the check only counts deferred channels.  If 6 L2CAP sockets
are connected at the same time in order DDDDND (D=deferred,
N=non-deferred), the last can bump the total to max+1.  It results to
one __le16 written out of bounds of the scid array, and an invalid
ECRED_CONN_REQ being sent.

Fix by leaving room for the non-deferred pending ECRED channels in the
counting in l2cap_chan_connect(), so the limit can't be exceeded.

Move counting under same critical section where the channel is added.
Although race conditions involving this appear unreachable, it's easier
to see.

Also add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this
less brittle.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version da49b602f7f75ccc91386e1274b3ef71676cd092
Version < ce0927eb3ee2939fab5ce3f9334bfd2fafb38481
Status affected
Version da49b602f7f75ccc91386e1274b3ef71676cd092
Version < 6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65
Status affected
Version da49b602f7f75ccc91386e1274b3ef71676cd092
Version < df8c3af6132640da4788e96a02d653e642059803
Status affected
Version da49b602f7f75ccc91386e1274b3ef71676cd092
Version < 56c2b5831d39dc84aad2573dc3e197af1a872a05
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ce0927eb3ee2939fab5ce3f9334bfd2fafb38481
https://git.kernel.org/stable/c/6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65
https://git.kernel.org/stable/c/df8c3af6132640da4788e96a02d653e642059803
https://git.kernel.org/stable/c/56c2b5831d39dc84aad2573dc3e197af1a872a05