CVE-2026-98107

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect l2cap_chan_connect() tries to ensure there are no more than L2CAP_ECRED_CONN_SCID_MAX pending ECRED channels, so they fit in the same L2CAP_ECRED_CONN_REQ that l2cap_ecred_connect() constructs. However, the check only counts deferred channels. If 6 L2CAP sockets are connected at the same time in order DDDDND (D=deferred, N=non-deferred), the last can bump the total to max+1. It results to one __le16 written out of bounds of the scid array, and an invalid ECRED_CONN_REQ being sent. Fix by leaving room for the non-deferred pending ECRED channels in the counting in l2cap_chan_connect(), so the limit can't be exceeded. Move counting under same critical section where the channel is added. Although race conditions involving this appear unreachable, it's easier to see. Also add WARN_ON_ONCE check in l2cap_ecred_defer_connect() to make this less brittle.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-30
Patch available
Yes

Affected versions

Linux kernel versions 5.7 and later are affected. Fixed in 6.12.111, 6.18.53, 7.2.7, 7.3-rc2 and their respective stable series.

Affected from
≥ 5.7
Fixed in
✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-98107?

    CVE-2026-98107 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.7 onward and has been patched in 6.12.111, 6.18.53, 7.2.7 and others. CVE-2026-98107 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98107?

    Yes. CVE-2026-98107 has been patched. Fixed versions include 6.12.111, 6.18.53, 7.2.7 and others. If you are running Linux kernel 5.7 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98107 actively exploited?

    No. CVE-2026-98107 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.