Bluetooth L2CAP Vulnerability in Linux Kernel
CVE-2026-98108

7.5HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98108?

A vulnerability in the Bluetooth L2CAP protocol within the Linux kernel allows for improper channel mode configurations when establishing connections. This occurs when the l2cap_le_connect_req() function fails to adjust the channel mode based on the parent channel's settings, leading to incorrect responses and potential out-of-bounds writes. The fix involves properly setting the channel mode during connection requests and implementing checks to prevent excessive deferred channels and duplicate identifiers, enhancing the stability and security of Bluetooth connections.

Affected Version(s)

Linux 15f02b91056253e8cdc592888f431da0731337b8

Linux 15f02b91056253e8cdc592888f431da0731337b8 < 564ae0e05e598aa895b9dbd18cb7d6eb64752869

Linux 15f02b91056253e8cdc592888f431da0731337b8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.