Improper control of a resource through its lifetime in Linux kernel - CVE-2026-63976
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in the Bluetooth L2CAP ECRED reconfiguration response handler when processing a replayed failure response after a successful reconfiguration. A remote attacker can replay a failure response with a stale ident value to cause a denial of service.
The issue can destroy an already-established channel by causing the kernel to match a subsequent response against a recycled ident value.
How to mitigate CVE-2026-63976
Sources
- https://git.kernel.org/stable/c/00e1950716c6ed67d74777b2db286b0fa23b4be9
- https://git.kernel.org/stable/c/3b5b5f423b4fd23404a393bda8adba3cd6f74ef1
- https://git.kernel.org/stable/c/59f5ecf6ad5c4db6ae81965a96156954a3b0d89a
- https://git.kernel.org/stable/c/8e7977afaef37c6bd2b2654f1bce6ab40d471147
- https://git.kernel.org/stable/c/ae0152d77d101c920769934fb102b18de0c6f526
- https://git.kernel.org/stable/c/c2afd2613fda90107c5e2fe8e855627451749c78
- https://git.kernel.org/stable/c/cc2b4f749de09975bfa06e58bbbad2f6acd4c79c
- https://git.kernel.org/stable/c/f39049304ba655ffcbb92edbdf8c51a1f1210bed