SB2026050615 - Type Confusion in Linux kernel bluetooth



SB2026050615 - Type Confusion in Linux kernel bluetooth

Published: May 6, 2026

Security Bulletin ID SB2026050615
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Type Confusion (CVE-ID: CVE-2026-43062)

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to type confusion in l2cap_ecred_reconf_rsp() when processing L2CAP_ECRED_RECONF_RSP packets. A remote attacker can send a specially crafted packet to cause a denial of service.

The issue causes valid packets to be rejected and may read the result field from an incorrect offset when the packet is large enough to pass the length check.


Remediation

Install update from vendor's website.