SB2026092532 - Out-of-bounds read in Linux kernel bluetooth
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-97408)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read beyond the advertised skb payload.
The vulnerability exists due to an out-of-bounds read in l2cap_recv_frame() when processing malformed connectionless L2CAP frames. A remote attacker can send a connectionless frame with an incomplete PSM payload to read beyond the advertised skb payload.
The read can use tailroom bytes as part of the PSM.
Remediation
Install update from vendor's website.