← All Advisories

CVE-2026-97408

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97408

Key Details

CVECVE-2026-97408
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: validate connectionless PSM length

Connectionless L2CAP frames carry a two-byte PSM at the start of the

payload. l2cap_recv_frame() currently reads that PSM unconditionally

after validating only the outer L2CAP length.

A malformed connectionless frame with a zero- or one-byte payload can

therefore make the parser read beyond the advertised skb payload and use

tailroom bytes as part of the PSM. A VHCI-backed QEMU reproducer

injected a one-byte connectionless payload and reached the unchecked

read.

Reject connectionless frames that cannot contain the PSM before reading

or pulling it. This preserves all valid connectionless frames while

dropping only structurally incomplete packets. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97408
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97408