Out-of-bounds read in Linux kernel - CVE-2026-97408

 

Out-of-bounds read in Linux kernel - CVE-2026-97408

Published: September 25, 2026


Vulnerability identifier: #VU152056
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97408
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read beyond the advertised skb payload.

The vulnerability exists due to an out-of-bounds read in l2cap_recv_frame() when processing malformed connectionless L2CAP frames. A remote attacker can send a connectionless frame with an incomplete PSM payload to read beyond the advertised skb payload.

The read can use tailroom bytes as part of the PSM.


Affected software

Linux kernel

How to mitigate CVE-2026-97408

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins