CVE-2026-64403: Bluetooth: L2CAP: validate option length before reading conf opt value
Bluetooth: L2CAP: validate option length before reading conf opt value
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Compensating control
Fix l2cap_get_conf_opt() at the source: pass the buffer end pointer into it, validate that the complete option (header plus value) fits before reading opt->val, and refuse to access opt->val unless opt->len bytes are present.
Event History
Frequently Asked Questions
What level of attacker access is required?
An attacker needs adjacent-network access via Bluetooth. No privileges or user interaction are required according to the CVSS vector.
Is this known to disclose kernel data in the current code path?
No. The existing post-hoc length check prevents the out-of-bounds value from being consumed, so the described current control flow is not considered a data leak.
Which products are identified as affected?
The affected software listed is the Linux kernel and Microsoft azl3 kernel 6.6.144.1-1.
What should teams do if they are affected?
Apply an available patch. The fix validates that the complete L2CAP configuration option is within the buffer before reading its value.