OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98108

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth L2CAP implementation, specifically in the handling of connection requests, which can lead to an out-of-bounds write due to improper channel mode settings. This flaw could potentially allow attackers to exploit the system, leading to instability or unauthorized access. Organizations using Linux systems with Bluetooth capabilities should prioritize addressing this issue to mitigate the associated risks.

CVE
CVE-2026-98108
Severity
HIGH
CVSS
7.5
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan l2cap_new_connection() sets default value of channel mode to match the parent channel. l2cap_le_connect_req() left this at the default, and created L2CAP_MODE_EXT_FLOWCTL channels if listening pchan has that mode. This causes FLAG_DEFER_SETUP channels to reply to L2CAP_LE_CONN_REQ with L2CAP_ECRED_CONN_RSP, which is incorrect. It can also result to stack OOB write (of l2cap_alloc_cid determined values) in l2cap_ecred_rsp_defer(), as l2cap_le_connect_req() does not limit maximum number of deferred channels or check for duplicate ident. Fix by setting chan->mode correctly in l2cap_le_connect_req(). Also check channel mode in l2cap_ecred_rsp_defer(), and do WARN_ON_ONCE instead of OOB write to make it less brittle.