CVE-2026-93783
Błąd w jądrze Linuxa w funkcji rfcomm_recv_frame umożliwia odczyt nieinicjalizowanej pamięci przez nieprawidłowe długości ramek.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame rfcomm_recv_frame() casts skb->data to struct rfcomm_hdr and dereferences hdr->addr and hdr->ctrl without validating skb->len first. A truncated frame with skb->len less than the minimum header size causes an out-of-bounds read of uninitialized memory. Additionally, a zero-length frame causes skb->len-- to underflow to UINT_MAX, making skb_tail_pointer() read far past the buffer. Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC handlers") fixed the same class of missing-length-check bugs in the MCC sub-handlers, but the top-level rfcomm_recv_frame() was left unfixed. KMSAN reports: BUG: KMSAN: uninit-value in rfcomm_run ... Uninit was created at: __alloc_skb+0x474/0xb60 vhci_write+0xe9/0x870 Fix this by rejecting frames smaller than sizeof(struct rfcomm_hdr) + 1 (the minimum frame must have a 3-byte header and a 1-byte FCS).
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:47 UTC |
- https://git.kernel.org/stable/c/30d1d9f3495463f7c026e4c553127f79b486fcd6 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/3829af5fab5a22405bf1e7d69068c2ec0fce46ca (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/67dc3b40fae71b6b11c71e7ff69bac0758818c05 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/b161eacd7fa4a2d765724b5504ac6cc388e48f80 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/b230e5bf501c5edaf2eb0991cb862ac142031d4b (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/bbc310caa2b6bf5fe42896ba27da0fbc12e4ac51 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fb40eda15122f6b780228639c1ead6820340ff54 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)