Out-of-bounds read in Linux kernel - CVE-2026-93783
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to read uninitialized memory.
The vulnerability exists due to an out-of-bounds read in rfcomm_recv_frame() when processing truncated Bluetooth RFCOMM frames. A remote attacker can send a truncated Bluetooth RFCOMM frame to read uninitialized memory.
A zero-length frame can cause a length underflow and make skb_tail_pointer() read past the buffer.