Bluetooth L2CAP Vulnerability in Linux Kernel
CVE-2026-98108
What is CVE-2026-98108?
A vulnerability in the Bluetooth L2CAP protocol within the Linux kernel allows for improper channel mode configurations when establishing connections. This occurs when the l2cap_le_connect_req() function fails to adjust the channel mode based on the parent channel's settings, leading to incorrect responses and potential out-of-bounds writes. The fix involves properly setting the channel mode during connection requests and implementing checks to prevent excessive deferred channels and duplicate identifiers, enhancing the stability and security of Bluetooth connections.
Affected Version(s)
Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux 15f02b91056253e8cdc592888f431da0731337b8 < 564ae0e05e598aa895b9dbd18cb7d6eb64752869
Linux 15f02b91056253e8cdc592888f431da0731337b8