CVE-2026-98247
Received Received - Intake

Bluetooth: hci_codec Validation Flaw in Linux Kernel

Vulnerability report for CVE-2026-98247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_codec: validate vendor codec count length The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array. If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6
Linux Linux 5.16

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper validation of Bluetooth codec data. The issue occurs when parsing Bluetooth controller replies that include standard and vendor codec arrays. The parser incorrectly calculates the size of the vendor codec array, potentially reading beyond the available data in the network packet. This leads to a buffer over-read vulnerability.

Detection Guidance

This vulnerability is specific to the Linux kernel's Bluetooth subsystem and requires kernel-level inspection. Detection involves checking kernel logs for Bluetooth-related errors or crashes, particularly during codec parsing. Commands like dmesg | grep -i bluetooth or journalctl -k | grep -i bluetooth may reveal issues. However, no direct commands are provided in the context to detect this exact vulnerability.

Impact Analysis

An attacker within Bluetooth range could exploit this to cause a denial of service by crashing the system or potentially leak kernel memory contents. Systems using vulnerable Linux kernel versions with Bluetooth functionality may be affected.

Mitigation Strategies

Immediate mitigation involves updating the Linux kernel to a patched version that resolves this issue. Check your distribution's security advisories for kernel updates. If no patch is available, consider disabling Bluetooth functionality temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98247. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart