Junglewise Threat Intelligence

CVE-2026-64403: Linux Kernel out-of-bounds read in Bluetooth L2CAP

CVE-2026-64403 · Severity: info · CVSS 3.1 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth implementation. It affects the L2CAP protocol, which is used to manage data between Bluetooth devices. An attacker could potentially trigger an improper memory read by sending specially crafted Bluetooth configuration requests. While current analysis suggests this does not lead to a direct data leak, it represents a security flaw that could be exploited if other parts of the system change.

Technical details

An out-of-bounds read exists in net/bluetooth/l2cap_core.c within the l2cap_get_conf_opt() function. The function derives an option length from an attacker-controlled field (opt->len) and dereferences the value before verifying that the buffer actually contains the specified number of bytes. This results in a validate-after-use bug where up to 4 bytes can be read past the buffer end. While existing post-hoc checks currently prevent the consumption of this garbage data, the flaw represents a fragile memory safety violation. The fix introduces an explicit buffer-end check before the value is accessed.

Affected products

  • Linux Linux Kernel 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 to cca81b4bc672604a84f6d224a55cc77ec7dee619

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References

Related threats