CVE-2026-31393 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that the payload is present: - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads 4 bytes past the header (needs cmd_len >= 8). - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header (needs cmd_len >= 5). A truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an out-of-bounds read of adjacent skb data. Guard each data access with the required payload length check. If the payload is too short, skip the read and let the state machine complete with safe defaults (feat_mask and remote_fixed_chan remain zero from kzalloc), so the info timer cleanup and l2cap_conn_start() still run and the connection is not stalled.
A vulnerability in the Linux kernel's Bluetooth L2CAP implementation allows for out-of-bounds reads due to improper validation of the L2CAP_INFO_RSP payload length. The issue arises in the l2cap_information_rsp() function, which processes the response without ensuring that the payload is complete. This flaw can be exploited by sending a truncated L2CAP_INFO_RSP with a specific result, leading to unauthorized access of adjacent data and potentially causing memory corruption.
The vulnerability has been addressed by adding proper payload length checks before accessing the L2CAP_INFO_RSP data. Users should upgrade to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/187e6fe939295be36063a1d91f8bebee04399a8c | kernel.org | Patch |
| https://git.kernel.org/stable/c/3b646516cba2ebc4b51a72954903326e7c1e443f | kernel.org | Patch |
| https://git.kernel.org/stable/c/5229e7d15771eac2b5886bfb1f976aea0c1eec14 | kernel.org | Patch |
| https://git.kernel.org/stable/c/807bd1258453c4c83f6ae9dbc1e7b44860ff40d0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9aeacde4da0f02d42fd968fd32f245828b230171 | kernel.org | Patch |
| https://git.kernel.org/stable/c/db2872d054e467810078e2b9f440a5b326a601b2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dd815e6e3918dc75a49aaabac36e4f024d675101 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e7ff754e339e3d5ce29aa9f95352d0186df8fbd9 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.24, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.20 >= 6.19, < 6.19.10 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 26, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 18, 2026 | CVE Modified | kernel.org |
| Apr 3, 2026 | New CVE Received | kernel.org |