CVE-2026-64403
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: L2CAP: validate option length before reading conf opt value<br />
<br />
l2cap_get_conf_opt() derives the option length from the<br />
attacker-controlled opt->len field and immediately dereferences<br />
opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a<br />
raw pointer for the default case) before any caller has confirmed<br />
that opt->len bytes are present in the buffer. The callers<br />
(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and<br />
l2cap_conf_rfc_get()) only detect a malformed option afterwards, once<br />
the running length has gone negative, by which point the<br />
out-of-bounds read has already executed.<br />
<br />
An existing post-hoc length check keeps the garbage value from being<br />
consumed, so this is not a data leak in the current control flow. It<br />
is still a validate-after-use ordering bug: up to 4 bytes are read<br />
past the end of the buffer before it is known to contain them, and it<br />
is fragile to future changes in the callers.<br />
<br />
Fix it at the source. Pass the end of the buffer into<br />
l2cap_get_conf_opt() and refuse to touch opt->val unless the full<br />
option (header + value) fits. Each caller computes an end pointer<br />
once before the loop and checks the return value directly instead of<br />
inferring the error from a negative length.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856
- https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a
- https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606
- https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b
- https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225
- https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b
- https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619
- https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd



