CVE-2026-98247
Received
Received - Intake
Bluetooth: hci_codec Validation Flaw in Linux Kernel
Vulnerability report for CVE-2026-98247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_codec: validate vendor codec count length
The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count. Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data. Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 8961987f3f5fa2f2618e72304d013c8dd5e604a6 |
| Linux | Linux | 5.16 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |