SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63976

HIGH · CVSS 8.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth L2CAP implementation, specifically in the handling of channel identifiers during reconfiguration. A remote attacker can exploit this flaw to replay failure responses using stale identifiers, potentially leading to the unintended termination of established Bluetooth channels. Organizations utilizing Linux in environments with Bluetooth capabilities should prioritize patching this vulnerability to mitigate risks associated with unauthorized channel disruptions.

CVE
CVE-2026-63976
Severity
HIGH
CVSS
8.8
EPSS
0.44%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success l2cap_ecred_reconf_rsp() returns early on success without clearing chan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp, l2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a successful transaction to prevent the channel from matching subsequent responses with the recycled ident value. A remote attacker that completed a reconfiguration as the peer can replay a failure response with the stale ident, causing the kernel to match and destroy the already-established channel via l2cap_chan_del(chan, ECONNRESET). Clear chan->ident for all matching channels on success, and harden the failure path by using l2cap_chan_hold_unless_zero() consistent with other L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident).