Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect
Summary
| CVE | CVE-2026-98107 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:41 UTC |
| Updated | 2026-09-30 14:10:59 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect l2cap_chan_connect() tries to ensure there are no more than L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the same L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs. However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one __le16 written out of bounds of the scid array, and an invalid ECRED_CONN_REQ being sent. Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap_chan_connect(), so the limit can't be exceeded. Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see. Also add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this less brittle. |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.054050000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected da49b602f7f75ccc91386e1274b3ef71676cd092 ce0927eb3ee2939fab5ce3f9334bfd2fafb38481 git | Not specified |
| CNA | Linux | Linux | affected da49b602f7f75ccc91386e1274b3ef71676cd092 6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65 git | Not specified |
| CNA | Linux | Linux | affected da49b602f7f75ccc91386e1274b3ef71676cd092 df8c3af6132640da4788e96a02d653e642059803 git | Not specified |
| CNA | Linux | Linux | affected da49b602f7f75ccc91386e1274b3ef71676cd092 56c2b5831d39dc84aad2573dc3e197af1a872a05 git | Not specified |
| CNA | Linux | Linux | affected 5.7 | Not specified |
| CNA | Linux | Linux | unaffected 5.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/56c2b5831d39dc84aad2573dc3e197af1a872a05 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/df8c3af6132640da4788e96a02d653e642059803 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ce0927eb3ee2939fab5ce3f9334bfd2fafb38481 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.