CVE-2026-98247EPSS p9.7%
CVE-2026-98247CVE-2026-98247
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_codec: validate vendor codec count length
The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count. Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data. Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |