CVE-2026-64403 (GCVE-0-2026-64403)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: validate option length before reading conf opt value
l2cap_get_conf_opt() derives the option length from the
attacker-controlled opt->len field and immediately dereferences
opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a
raw pointer for the default case) before any caller has confirmed
that opt->len bytes are present in the buffer. The callers
(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and
l2cap_conf_rfc_get()) only detect a malformed option afterwards, once
the running length has gone negative, by which point the
out-of-bounds read has already executed.
An existing post-hoc length check keeps the garbage value from being
consumed, so this is not a data leak in the current control flow. It
is still a validate-after-use ordering bug: up to 4 bytes are read
past the end of the buffer before it is known to contain them, and it
is fragile to future changes in the callers.
Fix it at the source. Pass the end of the buffer into
l2cap_get_conf_opt() and refuse to touch opt->val unless the full
option (header + value) fits. Each caller computes an end pointer
once before the loop and checks the return value directly instead of
inferring the error from a negative length.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 78c2887130f1a7d1883195732be1b6cdab667487 Version: ac7c597c465eb09391e40febbe088bdad601080b Version: ade4560e4fea198866e033fe1c02f063d6d7db2e Version: 99665dcf6ff803351b5e658f3a929cb498561e36 Version: 2b59d36f22622c92c0b06aee7571f0a86a217188 Version: 15d6538a0d6e0f6de5116081a948cba7cc3e1d3d Version: a556547bae00528f24b42786b41a14047db14b84 Version: 3.16.66 ≤ Version: 3.18.138 ≤ Version: 4.4.178 ≤ Version: 4.9.167 ≤ Version: 4.14.110 ≤ Version: 4.19.33 ≤ Version: 5.0.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cca81b4bc672604a84f6d224a55cc77ec7dee619",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "7d871e969b941ce25653f7716203a0ea4d07ad4b",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "98d93c226bdfaa79bbdd86981921d7f106374225",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "996d3da39899aceb8f4910911a3f19a45a7d9d1b",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "73abbaf91aa33da87c008fb62c148ade561bb606",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "6b47bdaacfd0045687880177e0987055d8f4765a",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "687617555cedfb74c9e3cb85d759b908dcb17856",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"status": "affected",
"version": "78c2887130f1a7d1883195732be1b6cdab667487",
"versionType": "git"
},
{
"status": "affected",
"version": "ac7c597c465eb09391e40febbe088bdad601080b",
"versionType": "git"
},
{
"status": "affected",
"version": "ade4560e4fea198866e033fe1c02f063d6d7db2e",
"versionType": "git"
},
{
"status": "affected",
"version": "99665dcf6ff803351b5e658f3a929cb498561e36",
"versionType": "git"
},
{
"status": "affected",
"version": "2b59d36f22622c92c0b06aee7571f0a86a217188",
"versionType": "git"
},
{
"status": "affected",
"version": "15d6538a0d6e0f6de5116081a948cba7cc3e1d3d",
"versionType": "git"
},
{
"status": "affected",
"version": "a556547bae00528f24b42786b41a14047db14b84",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.66",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.138",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.178",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.167",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.110",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.33",
"versionType": "semver"
},
{
"lessThan": "5.1",
"status": "affected",
"version": "5.0.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.66",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.138",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.110",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.0.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt-\u003elen field and immediately dereferences\nopt-\u003eval (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt-\u003elen bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt-\u003eval unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the loop and checks the return value directly instead of\ninferring the error from a negative length."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable parser processes attacker-controlled BR/EDR L2CAP configuration packets received from a Bluetooth peer within radio range.\nAC:L - A malformed option with a declared length exceeding the remaining buffer directly triggers the invalid read; no race or condition outside the attacker\u0027s control is required.\nPR:N - An unauthenticated Bluetooth peer can establish an SDP L2CAP channel, for which Linux bypasses the normal link-security check, and then submit configuration packets.\nUI:N - Once the Bluetooth interface is connectable with an applicable listening service, the peer can establish the channel and send the malformed option without victim action.\nS:U - The vulnerable Bluetooth parser and the resulting kernel impact are within the same host kernel security authority, without crossing a VM, sandbox, or IOMMU boundary.\nC:L - The invalid read is strictly bounded to at most four adjacent bytes. Although the post-hoc check prevents the value from being consumed in the current protocol flow, limited confidentiality impact is the higher defensible choice.\nI:N - The flaw performs only an out-of-bounds read, and the invalid value is discarded before option-specific processing; there is no memory write or control-flow corruption primitive.\nA:H - The invalid kernel read can produce an oops or panic when it reaches an inaccessible or hardened boundary, and an unauthenticated adjacent peer can repeatedly send malformed configuration options."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:01.248Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619"
},
{
"url": "https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd"
},
{
"url": "https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b"
},
{
"url": "https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225"
},
{
"url": "https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b"
},
{
"url": "https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606"
},
{
"url": "https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a"
},
{
"url": "https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856"
}
],
"title": "Bluetooth: L2CAP: validate option length before reading conf opt value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64403",
"datePublished": "2026-07-25T08:50:45.796Z",
"dateReserved": "2026-07-19T15:36:31.785Z",
"dateUpdated": "2026-08-17T04:55:01.248Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…