7.5

CVE-2026-98108

Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan

l2cap_new_connection() sets default value of channel mode to match the
parent channel.  l2cap_le_connect_req() left this at the default, and
created L2CAP_MODE_EXT_FLOWCTL channels if listening pchan has that
mode.  This causes FLAG_DEFER_SETUP channels to reply to
L2CAP_LE_CONN_REQ with L2CAP_ECRED_CONN_RSP, which is incorrect.

It can also result to stack OOB write (of l2cap_alloc_cid determined
values) in l2cap_ecred_rsp_defer(), as l2cap_le_connect_req() does not
limit maximum number of deferred channels or check for duplicate ident.

Fix by setting chan->mode correctly in l2cap_le_connect_req().

Also check channel mode in l2cap_ecred_rsp_defer(), and do WARN_ON_ONCE
instead of OOB write to make it less brittle.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < ad0f44a3f1f688558ed876a0702bc2c82b0df689
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 564ae0e05e598aa895b9dbd18cb7d6eb64752869
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < aab17938998b29e75c3324763411aef3e300fc67
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 0e1fc7cab95ad958e55d70a5dfaaea687c9c639f
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 1074bcc57f741223f9fa82ce6afe5c3d783e4d10
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 5d5a625cbc854d4c4f68e4b16fcf6e682d9a9ed1
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 6cb79e6499228cfdbd4b3301371ce74d01cd2f80
Status affected
Version 15f02b91056253e8cdc592888f431da0731337b8
Version < 4ef05db5b08b176a551b4a6287372045998806b0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.12
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1074bcc57f741223f9fa82ce6afe5c3d783e4d10
https://git.kernel.org/stable/c/5d5a625cbc854d4c4f68e4b16fcf6e682d9a9ed1
https://git.kernel.org/stable/c/6cb79e6499228cfdbd4b3301371ce74d01cd2f80
https://git.kernel.org/stable/c/4ef05db5b08b176a551b4a6287372045998806b0
https://git.kernel.org/stable/c/0e1fc7cab95ad958e55d70a5dfaaea687c9c639f
https://git.kernel.org/stable/c/564ae0e05e598aa895b9dbd18cb7d6eb64752869
https://git.kernel.org/stable/c/aab17938998b29e75c3324763411aef3e300fc67
https://git.kernel.org/stable/c/ad0f44a3f1f688558ed876a0702bc2c82b0df689