CVE-2026-63975

Source
https://cve.org/CVERecord?id=CVE-2026-63975
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63975.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63975
Downstream
Published
2026-07-19T14:56:00.662Z
Modified
2026-07-21T03:47:44.232189175Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix possible crash on l2capecredconn_rsp

If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2capchandel may invalidate the tmp cursor created by listforeachentrysafe and in fact it is the wrong procedure as the chan->dcid may be assigned previously it really needs to be disconnected.

Calling l2capchanclone directly may still lead to l2capchandel so instead schedule l2capchantimeout with delay 0 to close the channel asynchronously.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63975.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
15f02b91056253e8cdc592888f431da0731337b8
Fixed
3c8eaa91eb433c450426539290be4ffe282e9f00
Fixed
ecfed1e0d8efecad6737a0d83e21d2fd021d8c48
Fixed
e6833e737a51db1e5ea0401322acf5e22abd8be6
Fixed
6319b38fe69f56ed95680ade485b957a53fff642
Fixed
291eec1041c918c460dc9702e44edd17794b4a4b
Fixed
41e29548b5e8b5e5fcf708786b3bea67cab107fa
Fixed
d153b8898c0051eb8b6a083b35cbe304a5886bd5
Fixed
41c2713b204e6cb6a94587bc6bf6935107df5479

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63975.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63975.json"