In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame
rfcomm_recv_frame() casts skb->data to struct rfcomm_hdr and dereferences hdr->addr and hdr->ctrl without validating skb->len first. A truncated frame with skb->len less than the minimum header size causes an out-of-bounds read of uninitialized memory. Additionally, a zero-length frame causes skb->len-- to underflow to UINT_MAX, making skb_tail_pointer() read far past the buffer.
Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC handlers") fixed the same class of missing-length-check bugs in the MCC sub-handlers, but the top-level rfcomm_recv_frame() was left unfixed. KMSAN reports:
BUG: KMSAN: uninit-value in rfcomm_run ... Uninit was created at: __alloc_skb+0x474/0xb60 vhci_write+0xe9/0x870
Fix this by rejecting frames smaller than sizeof(struct rfcomm_hdr) + 1 (the minimum frame must have a 3-byte header and a 1-byte FCS).
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93783
- https://git.kernel.org/stable/c/67dc3b40fae71b6b11c71e7ff69bac0758818c05
- https://git.kernel.org/stable/c/b230e5bf501c5edaf2eb0991cb862ac142031d4b
- https://git.kernel.org/stable/c/bbc310caa2b6bf5fe42896ba27da0fbc12e4ac51
- https://git.kernel.org/stable/c/30d1d9f3495463f7c026e4c553127f79b486fcd6
- https://git.kernel.org/stable/c/3829af5fab5a22405bf1e7d69068c2ec0fce46ca
- https://git.kernel.org/stable/c/b161eacd7fa4a2d765724b5504ac6cc388e48f80
- https://git.kernel.org/stable/c/fb40eda15122f6b780228639c1ead6820340ff54
- https://github.com/advisories/GHSA-xv96-c36m-qhm7