L2CAP Reconfiguration Flaw in Linux Kernel Affects Bluetooth Functionality
CVE-2026-63976
What is CVE-2026-63976?
A vulnerability exists in the Linux kernel's Bluetooth subsystem, specifically affecting the L2CAP protocol. This issue arises from inadequate clearing of the channel identifier upon successful reconfiguration during the l2cap_ecred_reconf_rsp() operation. This oversight can enable a remote attacker, who has successfully executed a prior reconfiguration, to exploit the stale channel identifier. By replaying a failure response with the recycled identifier, the attacker can force the kernel to wrongly associate the identifier with an already established channel. This can lead to unintended termination of active Bluetooth connections, undermining the integrity of Bluetooth communication. Enhancements have been applied to ensure that the channel identifier is properly cleared and secured in subsequent transactions.
Affected Version(s)
Linux 15f02b91056253e8cdc592888f431da0731337b8 < 59f5ecf6ad5c4db6ae81965a96156954a3b0d89a
Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux 15f02b91056253e8cdc592888f431da0731337b8