Out-of-bounds read in Linux kernel - CVE-2026-97408
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to read beyond the advertised skb payload.
The vulnerability exists due to an out-of-bounds read in l2cap_recv_frame() when processing malformed connectionless L2CAP frames. A remote attacker can send a connectionless frame with an incomplete PSM payload to read beyond the advertised skb payload.
The read can use tailroom bytes as part of the PSM.