CVE-2026-98247 PUBLISHED

Bluetooth: hci_codec: validate vendor codec count length

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_codec: validate vendor codec count length

The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array.

If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to 9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8 (excl.)
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to a6da782fefae611e68a1aa79644065fc8ca5abcd (excl.)
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to e4cfd3c4299105237458b27958bd7b0aa4c60795 (excl.)
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to f49a543d76d48f184b34225d9c0e2fc4cbdea8ec (excl.)
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to 12a82819b0cada6e304790b1097f8f9006eb6123 (excl.)
  • affected from 8961987f3f5fa2f2618e72304d013c8dd5e604a6 to d0795cfd6f655f4de84868a4f4bb41a03f037b3d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.16 is affected
  • unaffected from 0 to 5.16 (excl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References