Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98247— Bluetooth: hci_codec: validate vendor codec count length

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 蓝牙:hci_codec:验证供应商编解码器数量长度 在读取本地支持编解码器时,解析器在处理供应商编解码器数量之前,先消费了变长的标准编解码器数组。尽管初始回复大小检查在固定布局中包含了一个供应商数量字节,但该检查并不能保证该字节在标准编解码器数组之后仍然存在。 如果控制器的回复在该数组结束后立即终止,那么计算供应商编解码器数组大小时会读取 超出 skb(socket buffer,套接字缓冲区)数据范围的内容。因此,在两种命令变体中,应先使用 验证并消费每个编解码器头,再

AI Predicted 5.5 Difficulty: Hard EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6< 9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8 affected
8961987f3f5fa2f2618e72304d013c8dd5e604a6< a6da782fefae611e68a1aa79644065fc8ca5abcd affected
8961987f3f5fa2f2618e72304d013c8dd5e604a6< e4cfd3c4299105237458b27958bd7b0aa4c60795 affected
8961987f3f5fa2f2618e72304d013c8dd5e604a6< f49a543d76d48f184b34225d9c0e2fc4cbdea8ec affected
8961987f3f5fa2f2618e72304d013c8dd5e604a6< 12a82819b0cada6e304790b1097f8f9006eb6123 affected
8961987f3f5fa2f2618e72304d013c8dd5e604a6< d0795cfd6f655f4de84868a4f4bb41a03f037b3d affected
5.16 affected
< 5.16 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98247

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluetooth: hci_codec: validate vendor codec count length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_codec: validate vendor codec count length The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array. If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8961987f3f5fa2f2618e72304d013c8dd5e604a6 ~ 9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8 -
Linux Linux 5.16 -

II. Public POCs for CVE-2026-98247

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98247

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98247 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98247

No comments yet


Leave a comment