Answer in brief
CVE-2026-98247 records a Unknown severity vulnerability in Bluetooth: hci_codec: validate vendor codec count length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8 || >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <a6da782fefae611e68a1aa79644065fc8ca5abcd || >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <e4cfd3c4299105237458b27958bd7b0aa4c60795 || >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <f49a543d76d48f184b34225d9c0e2fc4cbdea8ec || >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <12a82819b0cada6e304790b1097f8f9006eb6123 || >=8961987f3f5fa2f2618e72304d013c8dd5e604a6 <d0795cfd6f655f4de84868a4f4bb41a03f037b3d | 9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8, a6da782fefae611e68a1aa79644065fc8ca5abcd, e4cfd3c4299105237458b27958bd7b0aa4c60795, f49a543d76d48f184b34225d9c0e2fc4cbdea8ec, 12a82819b0cada6e304790b1097f8f9006eb6123, d0795cfd6f655f4de84868a4f4bb41a03f037b3d |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_codec: validate vendor codec count length The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array. If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.
Quoted source text, attributed separately from HOL analysis.