Bluetooth Vulnerability in Linux Kernel Affecting Multiple Versions
CVE-2026-63975
What is CVE-2026-63975?
In the Linux kernel, a vulnerability was identified in the Bluetooth subsystem that affects the handling of L2CAP connections. The issue arises when a destination channel ID (dcid) is received for an already-assigned channel. This can result in a potential crash due to improper management of channel deletion that may invalidate necessary temporary pointers and compromise channel disconnection protocols. To mitigate this, adjustments have been made to ensure that channels are gracefully discarded without leading to instability, including scheduling a timeout for channel closure.
Affected Version(s)
Linux 15f02b91056253e8cdc592888f431da0731337b8 < 3c8eaa91eb433c450426539290be4ffe282e9f00
Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux 15f02b91056253e8cdc592888f431da0731337b8