Executive brief
A security vulnerability has been identified in the Linux kernel's Bluetooth subsystem. This flaw could allow a local user to cause a system crash or potentially access sensitive kernel memory. The issue stems from how the system handles configuration requests for Bluetooth connections, specifically failing to verify the size of data provided by a user before processing it.
Technical details
A vulnerability exists in the L2CAP component of the Linux kernel Bluetooth stack (net/bluetooth/l2cap_sock.c). The functions l2cap_sock_setsockopt and l2cap_sock_setsockopt_old failed to properly validate the 'optlen' parameter before copying data from user space using copy_from_sockptr. This improper validation of specified quantity in input (CWE-1284) allows a local attacker with low privileges to trigger an out-of-bounds read or kernel memory corruption. The fix replaces direct copy calls with bt_copy_from_sockptr, which enforces strict length checks against the expected structure size. Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.39 to 5.10.227, 5.11 to 6.1.87, 6.2 to 6.6.55, 6.7 to 6.8.7, 6.9-rc1 to 6.9-rc3
Timeline
- 2024-05-20: advisory: NVD published the vulnerability record.
- 2024-04-10: patched: Initial patch committed to the Linux kernel tree.
References
- https://git.kernel.org/stable/c/28234f8ab69c522ba447f3e041bbfbb284c5959a
- https://git.kernel.org/stable/c/4f3951242ace5efc7131932e2e01e6ac6baed846
- https://git.kernel.org/stable/c/8ee0c132a61df9723813c40e742dc5321824daa9
- https://git.kernel.org/stable/c/9d42f373391211c7c8af66a3a316533a32b8a607
- https://git.kernel.org/stable/c/f13b04cf65a86507ff15a9bbf37969d25be3e2a0
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html