Review reviewHigh

CVE-2026-63976

Linux

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success l2cap_ecred_reconf_rsp() returns early on success without clearing chan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp, l2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a successful transaction to prevent the channel from matching subsequent responses with the recycled ident value. A remote attacker that completed a reconfiguration as the peer can replay a failure response with the stale ident, causing the kernel to match...

CVSS
8.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success l2cap_ecred_reconf_rsp() returns early on success without clearing chan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp, l2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a successful transaction to prevent the channel from matching subsequent responses with the recycled ident value. A remote attacker that completed a reconfiguration as the peer can replay a failure response with the stale ident, causing the kernel to match...

Affected product and versions

Product
Linux
Affected versions
>= 15f02b91056253e8cdc592888f431da0731337b8 < 59f5ecf6ad5c4db6ae81965a96156954a3b0d89a, >= 15f02b91056253e8cdc592888f431da0731337b8 < ae0152d77d101c920769934fb102b18de0c6f526, >= 15f02b91056253e8cdc592888f431da0731337b8 < c2afd2613fda90107c5e2fe8e855627451749c78, >= 15f02b91056253e8cdc592888f431da0731337b8 < cc2b4f749de09975bfa06e58bbbad2f6acd4c79c, >= 15f02b91056253e8cdc592888f431da0731337b8 < 3b5b5f423b4fd23404a393bda8adba3cd6f74ef1, >= 15f02b91056253e8cdc592888f431da0731337b8 < f39049304ba655ffcbb92edbdf8c51a1f1210bed, >= 15f02b91056253e8cdc592888f431da0731337b8 < 8e7977afaef37c6bd2b2654f1bce6ab40d471147, >= 15f02b91056253e8cdc592888f431da0731337b8 < 00e1950716c6ed67d74777b2db286b0fa23b4be9, >= 5.7
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-63976 — Linux | SECUFOCUS NOW