Bluetooth: L2CAP: validate option length before reading conf opt value

Summary

CVECVE-2026-64403
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:23 UTC
Updated2026-07-27 05:16:47 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately dereferences opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a raw pointer for the default case) before any caller has confirmed that opt->len bytes are present in the buffer. The callers (l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and l2cap_conf_rfc_get()) only detect a malformed option afterwards, once the running length has gone negative, by which point the out-of-bounds read has already executed. An existing post-hoc length check keeps the garbage value from being consumed, so this is not a data leak in the current control flow. It is still a validate-after-use ordering bug: up to 4 bytes are read past the end of the buffer before it is known to contain them, and it is fragile to future changes in the callers. Fix it at the source. Pass the end of the buffer into l2cap_get_conf_opt() and refuse to touch opt->val unless the full option (header + value) fits. Each caller computes an end pointer once before the loop and checks the return value directly instead of inferring the error from a negative length.

Risk And Classification

Primary CVSS: v3.1 7.1 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

EPSS: 0.002650000 probability, percentile 0.182100000 (date 2026-07-27)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
3.1CNADECLARED7.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 cca81b4bc672604a84f6d224a55cc77ec7dee619 git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 f70d4aa88068096f35d73e3a05eff33c0a16b9cd git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 7d871e969b941ce25653f7716203a0ea4d07ad4b git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 98d93c226bdfaa79bbdd86981921d7f106374225 git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 996d3da39899aceb8f4910911a3f19a45a7d9d1b git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 73abbaf91aa33da87c008fb62c148ade561bb606 git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 6b47bdaacfd0045687880177e0987055d8f4765a git Not specified
CNA Linux Linux affected 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 687617555cedfb74c9e3cb85d759b908dcb17856 git Not specified
CNA Linux Linux affected 78c2887130f1a7d1883195732be1b6cdab667487 git Not specified
CNA Linux Linux affected ac7c597c465eb09391e40febbe088bdad601080b git Not specified
CNA Linux Linux affected ade4560e4fea198866e033fe1c02f063d6d7db2e git Not specified
CNA Linux Linux affected 99665dcf6ff803351b5e658f3a929cb498561e36 git Not specified
CNA Linux Linux affected 2b59d36f22622c92c0b06aee7571f0a86a217188 git Not specified
CNA Linux Linux affected 15d6538a0d6e0f6de5116081a948cba7cc3e1d3d git Not specified
CNA Linux Linux affected a556547bae00528f24b42786b41a14047db14b84 git Not specified
CNA Linux Linux affected 3.16.66 3.17 semver Not specified
CNA Linux Linux affected 3.18.138 3.19 semver Not specified
CNA Linux Linux affected 4.4.178 4.5 semver Not specified
CNA Linux Linux affected 4.9.167 4.10 semver Not specified
CNA Linux Linux affected 4.14.110 4.15 semver Not specified
CNA Linux Linux affected 4.19.33 4.20 semver Not specified
CNA Linux Linux affected 5.0.6 5.1 semver Not specified
CNA Linux Linux affected 5.1 Not specified
CNA Linux Linux unaffected 5.1 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report