CVE-2026-98247

Source
https://cve.org/CVERecord?id=CVE-2026-98247
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98247.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98247
Downstream
Published
2026-10-06T08:45:16Z
Modified
2026-10-07T02:47:33Z
Summary
Bluetooth: hci_codec: validate vendor codec count length
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_codec: validate vendor codec count length

The Read Local Supported Codecs parsers consume the variable-sized standard codec array before parsing the vendor codec count. Although the initial reply-size check includes a vendor count byte in the fixed layout, it does not guarantee that the byte remains after the standard codec array.

If a controller reply ends immediately after that array, calculating the vendor codec array size reads vnd_codecs->num beyond the skb data. Use skb_pull_data() to validate and consume each codec header before using its count in both command variants.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98247.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8961987f3f5fa2f2618e72304d013c8dd5e604a6
Fixed
9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8
Fixed
a6da782fefae611e68a1aa79644065fc8ca5abcd
Fixed
e4cfd3c4299105237458b27958bd7b0aa4c60795
Fixed
f49a543d76d48f184b34225d9c0e2fc4cbdea8ec
Fixed
12a82819b0cada6e304790b1097f8f9006eb6123
Fixed
d0795cfd6f655f4de84868a4f4bb41a03f037b3d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98247.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98247.json"