Skip to main content
Vulnerability Database/CVE-2026-98107

CVE-2026-98107: Linux Kernel Bluetooth Buffer Overflow

CVE-2026-98107 is a buffer overflow flaw in Linux kernel Bluetooth L2CAP that allows out-of-bounds writes in ECRED channel connections. This post explains the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-98107 Overview

CVE-2026-98107 is an out-of-bounds write vulnerability in the Linux kernel's Bluetooth Enhanced Credit Based Flow Control (ECRED) implementation. The flaw resides in the l2cap_ecred_connect() function within the L2CAP (Logical Link Control and Adaptation Protocol) subsystem. The counting logic in l2cap_chan_connect() only tracks deferred channels when enforcing the L2CAP_ECRED_CONN_SCID_MAX limit. A specific connection sequence of six L2CAP sockets allows the total to exceed the maximum by one, triggering an out-of-bounds __le16 write into the scid array and producing a malformed ECRED_CONN_REQ.

Critical Impact

An out-of-bounds kernel memory write in the Bluetooth stack can cause memory corruption, kernel panic, or create conditions for further exploitation on affected Linux systems.

Affected Products

  • Linux kernel (Bluetooth L2CAP subsystem)
  • Distributions shipping affected kernel versions prior to the referenced stable commits
  • Systems with Bluetooth hardware and the L2CAP ECRED code path enabled

Discovery Timeline

  • 2026-09-25 - CVE-2026-98107 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98107

Vulnerability Analysis

The vulnerability resides in the Linux kernel Bluetooth L2CAP ECRED connection path. l2cap_chan_connect() enforces an upper bound of L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels so they fit in a single L2CAP_ECRED_CONN_REQ built by l2cap_ecred_connect(). The accounting only counts deferred channels, ignoring non-deferred pending channels sharing the same request structure.

An attacker-controlled sequence of six L2CAP socket connections in the order deferred-deferred-deferred-deferred-non-deferred-deferred raises the total pending channel count to L2CAP_ECRED_CONN_SCID_MAX + 1. The sixth channel index exceeds the fixed-size scid array bounds, resulting in a 16-bit write past the end of the array and emission of a malformed connection request.

Root Cause

The root cause is an off-by-one accounting error. The check in l2cap_chan_connect() fails to reserve capacity for non-deferred pending ECRED channels. Because both deferred and non-deferred entries ultimately populate the same scid[] array in the L2CAP_ECRED_CONN_REQ packet, undercounting one class permits the array index to advance beyond its allocated capacity. This is an out-of-bounds write classified under memory corruption [CWE-787].

Attack Vector

Exploitation requires local access to open multiple L2CAP sockets and drive specific ECRED connection sequences. The attacker opens L2CAP sockets in the triggering order to force the bounds check to pass while causing the array index to overrun by one __le16 slot. The upstream fix adjusts the counting in l2cap_chan_connect() to include non-deferred pending ECRED channels, moves the counting into the critical section protecting channel addition, and adds a WARN_ON_ONCE check in l2cap_ecred_defer_connect() for defense in depth.

No verified public exploit code is referenced in the NVD entry. See the upstream patches for technical details: Kernel commit 56c2b58, Kernel commit 6da5c03, Kernel commit ce0927e, and Kernel commit df8c3af.

Detection Methods for CVE-2026-98107

Indicators of Compromise

  • Unexpected kernel oops or panic traces referencing l2cap_ecred_connect, l2cap_chan_connect, or neighboring L2CAP symbols.
  • Kernel log entries containing WARN_ON_ONCE warnings from l2cap_ecred_defer_connect() after the patch is applied.
  • Malformed or truncated L2CAP_ECRED_CONN_REQ packets observed in Bluetooth HCI traces.

Detection Strategies

  • Inventory kernel versions across Linux endpoints and flag hosts running Bluetooth-enabled kernels built before the referenced stable commits.
  • Monitor dmesg and journalctl -k for KASAN, slab-out-of-bounds, or BUG reports originating in net/bluetooth/l2cap_core.c.
  • Correlate kernel crash telemetry with processes holding L2CAP sockets to identify abnormal connection patterns.

Monitoring Recommendations

  • Centralize kernel log forwarding so Bluetooth stack warnings are captured for review.
  • Track Bluetooth adapter enable or disable events on systems where Bluetooth is not required operationally.
  • Alert on repeated short-lived L2CAP connection sequences from the same user context, which may indicate exploitation attempts.

How to Mitigate CVE-2026-98107

Immediate Actions Required

  • Apply the stable kernel update that includes the referenced upstream commits as soon as distribution packages are available.
  • Disable the Bluetooth kernel modules (rmmod bluetooth btusb) on servers and workstations that do not require Bluetooth connectivity.
  • Restrict local account access on multi-user systems until the patched kernel is deployed and the host is rebooted.

Patch Information

The fix is distributed across four upstream stable kernel commits that correct the pending channel accounting, move counting under the correct critical section, and add a WARN_ON_ONCE guard in l2cap_ecred_defer_connect(). Reference commits: 56c2b58, 6da5c03, ce0927e, and df8c3af. Rebuild and reboot into the patched kernel to activate the mitigation.

Workarounds

  • Blacklist the bluetooth and btusb modules through /etc/modprobe.d/ on systems where wireless personal area networking is unnecessary.
  • Disable the Bluetooth service via systemctl disable --now bluetooth.service to reduce exposure of the L2CAP code path.
  • Enforce least-privilege policies to limit which local users can open raw L2CAP sockets.
bash
# Configuration example: disable Bluetooth stack until the patched kernel is deployed
sudo systemctl disable --now bluetooth.service
echo 'blacklist bluetooth' | sudo tee /etc/modprobe.d/disable-bluetooth.conf
echo 'blacklist btusb' | sudo tee -a /etc/modprobe.d/disable-bluetooth.conf
sudo update-initramfs -u
sudo reboot

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.