SB2026092532 - Out-of-bounds read in Linux kernel bluetooth



SB2026092532 - Out-of-bounds read in Linux kernel bluetooth

Published: September 25, 2026

Security Bulletin ID SB2026092532
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-97408)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read beyond the advertised skb payload.

The vulnerability exists due to an out-of-bounds read in l2cap_recv_frame() when processing malformed connectionless L2CAP frames. A remote attacker can send a connectionless frame with an incomplete PSM payload to read beyond the advertised skb payload.

The read can use tailroom bytes as part of the PSM.


Remediation

Install update from vendor's website.