PT-2026-30176 · Linux · Linux Kernel

Published

2026-04-03

·

Updated

2026-05-22

·

CVE-2026-31393

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the Bluetooth L2CAP implementation. Specifically, the l2cap information rsp() function does not adequately validate the length of the L2CAP INFO RSP payload before accessing it, potentially leading to out-of-bounds reads. This occurs when a truncated L2CAP INFO RSP message with a success result is received. The function l2cap information rsp() is vulnerable. The vulnerable parameters include rsp->data. Specifically, get unaligned le32(rsp->data) and rsp->data[0] are accessed without proper bounds checking.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-31393
ECHO-C4C1-8755-0A86
OESA-2026-1946
OESA-2026-1947
OESA-2026-1948
OESA-2026-2416
OESA-2026-2419

Affected Products

Linux Kernel