Answer in brief
CVE-2026-98107 records a Unknown severity vulnerability in Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=da49b602f7f75ccc91386e1274b3ef71676cd092 <ce0927eb3ee2939fab5ce3f9334bfd2fafb38481 || >=da49b602f7f75ccc91386e1274b3ef71676cd092 <6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65 || >=da49b602f7f75ccc91386e1274b3ef71676cd092 <df8c3af6132640da4788e96a02d653e642059803 || >=da49b602f7f75ccc91386e1274b3ef71676cd092 <56c2b5831d39dc84aad2573dc3e197af1a872a05 | ce0927eb3ee2939fab5ce3f9334bfd2fafb38481, 6da5c0331fc3ef0c7b8df8269523fc3b2cce1e65, df8c3af6132640da4788e96a02d653e642059803, 56c2b5831d39dc84aad2573dc3e197af1a872a05 |
| Linux/Linuxgeneric | 5.7 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect l2cap_chan_connect() tries to ensure there are no more than L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the same L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs. However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one __le16 written out of bounds of the scid array, and an invalid ECRED_CONN_REQ being sent. Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap_chan_connect(), so the limit can't be exceeded. Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see. Also add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this less brittle.
Quoted source text, attributed separately from HOL analysis.