{"id":"CVE-2026-97408","published":"2026-09-24T17:17:18.337","lastModified":"2026-09-25T13:17:24.337","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate connectionless PSM length\n\nConnectionless L2CAP frames carry a two-byte PSM at the start of the\npayload.  l2cap_recv_frame() currently reads that PSM unconditionally\nafter validating only the outer L2CAP length.\n\nA malformed connectionless frame with a zero- or one-byte payload can\ntherefore make the parser read beyond the advertised skb payload and use\ntailroom bytes as part of the PSM.  A VHCI-backed QEMU reproducer\ninjected a one-byte connectionless payload and reached the unchecked\nread.\n\nReject connectionless frames that cannot contain the PSM before reading\nor pulling it.  This preserves all valid connectionless frames while\ndropping only structurally incomplete packets.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/3502ede8aed3c3ee1786d952a11054ac737d1a38","tags":[]},{"url":"https://git.kernel.org/stable/c/a40a5f922546b3bd7c094d882b29177db4f2abe0","tags":[]},{"url":"https://git.kernel.org/stable/c/ae69dca122f6d6046a68cf40153e6e827c77ff5c","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}