CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv()
Published Apr 22, 2026
·Updated
Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2capecreddatarcv()
Affected Software
16 affected components
Linux Linux kernel
Linux Linux kernel>=3.14.1<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.168
Linux Linux kernel>=6.2<6.6.131
Linux Linux kernel>=6.7<6.12.80
Linux Linux kernel>=6.13<6.18.21
Linux Linux kernel>=6.19<6.19.11
Linux Linux kernel=3.14
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Event History
Apr 22, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityAffected Software
Apr 23, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-31512?
CVE-2026-31512 is classified as a medium severity vulnerability.
2
How do I fix CVE-2026-31512?
To fix CVE-2026-31512, update the Linux kernel to the latest stable version that includes the patch.
3
What are the potential impacts of CVE-2026-31512?
CVE-2026-31512 could allow an attacker to exploit the Bluetooth L2CAP signaling channel and potentially disrupt Bluetooth services.
4
Which versions of the Linux kernel are affected by CVE-2026-31512?
CVE-2026-31512 affects specific versions of the Linux kernel prior to the implementation of the security patch.
5
Is CVE-2026-31512 associated with a specific Bluetooth component?
Yes, CVE-2026-31512 is associated with the L2CAP layer in the Bluetooth stack of the Linux kernel.