Executive brief
A vulnerability in the Linux kernel's Bluetooth component could allow a local user to cause a system crash. This occurs when the system is under heavy memory pressure while processing specific Bluetooth network traffic. While it does not directly expose data, it can impact the reliability and availability of devices using Bluetooth Low Energy (LE) networking.
Technical details
A vulnerability exists in the net/bluetooth/6lowpan.c component of the Linux kernel. The function send_mcast_pkt() calls skb_clone() to duplicate socket buffers for multicast packets but fails to validate the return value. If the system is low on memory, skb_clone() returns NULL; subsequent dereferencing of this pointer in send_pkt() leads to a kernel NULL pointer dereference and system crash (DoS). This issue affects Bluetooth Low Energy (LE) devices utilizing 6LoWPAN. Patches have been released across multiple stable kernel branches to add the necessary NULL checks.
Affected products
- Linux Linux Kernel 3.14 to 6.6.143
Timeline
- 2026-05-26: other: Vulnerability fixed in upstream kernel code
- 2026-07-19: disclosed: CVE-2026-63991 published
References
- https://git.kernel.org/stable/c/2061d080a013c0ec0a56162cd501fb36d2befc26
- https://git.kernel.org/stable/c/3c40d381ce04f9575a5d8b542898183c3b4b38dc
- https://git.kernel.org/stable/c/3d5d81d294ba09487c86bc4ba33dc4a4bec5d215
- https://git.kernel.org/stable/c/9903a04becf059e44cccf625e23689b7d4378384
- https://git.kernel.org/stable/c/9afcb5ea080af13aab37930da627db43bd277665
- https://git.kernel.org/stable/c/b06203ac5f12929d79146bb9f063c2af1d679e63
- https://git.kernel.org/stable/c/d630c4b25f36e0e68461561e4c70957ec37fdedd