Review reviewHigh

CVE-2026-31393

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that the payload is present: - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads 4 bytes past the header (needs cmd_len >= 8). - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header (needs cmd_len >= 5). A truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an out-...

CVSS
8.1
EPSS
0.26%
17.0% percentile
CISA KEV
Not listed
Published
2026.04.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.26%
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that the payload is present: - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads 4 bytes past the header (needs cmd_len >= 8). - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header (needs cmd_len >= 5). A truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an out-...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 4e8402a3f884427f9233ba436459c158d1f2e114 < 187e6fe939295be36063a1d91f8bebee04399a8c, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < 5229e7d15771eac2b5886bfb1f976aea0c1eec14, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < 3b646516cba2ebc4b51a72954903326e7c1e443f, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < 807bd1258453c4c83f6ae9dbc1e7b44860ff40d0, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < 9aeacde4da0f02d42fd968fd32f245828b230171, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < e7ff754e339e3d5ce29aa9f95352d0186df8fbd9, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < db2872d054e467810078e2b9f440a5b326a601b2, >= 4e8402a3f884427f9233ba436459c158d1f2e114 < dd815e6e3918dc75a49aaabac36e4f024d675101, >= 2.6.24, >= 2.6.24 < 5.10.253, >= 5.11 < 5.15.203, >= 5.16 < 6.1.167, >= 6.2 < 6.6.130, >= 6.7 < 6.12.78, >= 6.13 < 6.18.20, >= 6.19 < 6.19.10, 7.0
Fixed versions
5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2026-31393 — Linux Linux, linux kernel | SECUFOCUS NOW