Out-of-bounds write in Linux kernel - CVE-2026-98107
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in the L2CAP ECRED connection handling when connecting a sequence of L2CAP sockets with deferred and non-deferred channels. A local user can initiate the socket connection sequence to write a 16-bit SCID value past the SCID array.