Stack-based buffer overflow in Linux kernel - CVE-2026-98108
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to a stack-based buffer overflow in the Bluetooth L2CAP deferred enhanced credit-based response handling when processing L2CAP LE connection requests. A remote attacker can send specially crafted L2CAP LE connection requests to cause memory corruption.
The issue involves deferred-setup channels and listening parent channels configured for extended flow control.