CVE-2026-98247
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_codec: validate vendor codec count length The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array. If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/12a82819b0cada6e304790b1097f8f9006eb6123
- https://git.kernel.org/stable/c/9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8
- https://git.kernel.org/stable/c/a6da782fefae611e68a1aa79644065fc8ca5abcd
- https://git.kernel.org/stable/c/d0795cfd6f655f4de84868a4f4bb41a03f037b3d
- https://git.kernel.org/stable/c/e4cfd3c4299105237458b27958bd7b0aa4c60795
- https://git.kernel.org/stable/c/f49a543d76d48f184b34225d9c0e2fc4cbdea8ec
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.