Executive brief
A vulnerability in the Linux kernel's Bluetooth component could allow an attacker within Bluetooth range to read sensitive information from the system's memory. This occurs because the system fails to properly check the size of incoming Bluetooth control messages before reading them. An exploit could lead to the exposure of private data or cause a system crash, potentially disrupting wireless connectivity and operations.
Technical details
An out-of-bounds read vulnerability exists in the l2cap_information_rsp() function within net/bluetooth/l2cap_core.c. The function validates that the command length covers the fixed 4-byte header but fails to verify the presence of the subsequent payload before reading. Specifically, L2CAP_IT_FEAT_MASK attempts to read 4 bytes and L2CAP_IT_FIXED_CHAN attempts to read 1 byte past the header. A truncated L2CAP_INFO_RSP packet with a success result triggers a read of adjacent socket buffer (skb) data. This can be exploited by an unauthenticated attacker via an adjacent network (Bluetooth range) to disclose kernel memory or cause a denial of service. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4e8402a3f884 to 6.13
Timeline
- 2026-03-10: other: Vulnerability fixed in upstream source code
- 2026-04-03: disclosed: CVE published
References
- https://git.kernel.org/stable/c/187e6fe939295be36063a1d91f8bebee04399a8c
- https://git.kernel.org/stable/c/3b646516cba2ebc4b51a72954903326e7c1e443f
- https://git.kernel.org/stable/c/5229e7d15771eac2b5886bfb1f976aea0c1eec14
- https://git.kernel.org/stable/c/807bd1258453c4c83f6ae9dbc1e7b44860ff40d0
- https://git.kernel.org/stable/c/9aeacde4da0f02d42fd968fd32f245828b230171
- https://git.kernel.org/stable/c/db2872d054e467810078e2b9f440a5b326a601b2
- https://git.kernel.org/stable/c/dd815e6e3918dc75a49aaabac36e4f024d675101