CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's Bluetooth L2CAP implementation, specifically in the handling of channel identifiers during reconfiguration. A remote attacker can exploit this flaw to replay failure responses using stale identifiers, potentially leading to the unintended termination of established Bluetooth channels. Organizations utilizing Linux in environments with Bluetooth capabilities should prioritize patching this vulnerability to mitigate risks associated with unauthorized channel disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success l2cap_ecred_reconf_rsp() returns early on success without clearing chan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp, l2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a successful transaction to prevent the channel from matching subsequent responses with the recycled ident value. A remote attacker that completed a reconfiguration as the peer can replay a failure response with the stale ident, causing the kernel to match and destroy the already-established channel via l2cap_chan_del(chan, ECONNRESET). Clear chan->ident for all matching channels on success, and harden the failure path by using l2cap_chan_hold_unless_zero() consistent with other L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident).