{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63976","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.024Z","datePublished":"2026-07-19T14:56:01.284Z","dateUpdated":"2026-08-05T12:37:47.072Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:37:47.072Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: clear chan->ident on ECRED reconfiguration success\n\nl2cap_ecred_reconf_rsp() returns early on success without clearing\nchan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp,\nl2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a\nsuccessful transaction to prevent the channel from matching subsequent\nresponses with the recycled ident value.\n\nA remote attacker that completed a reconfiguration as the peer can\nreplay a failure response with the stale ident, causing the kernel to\nmatch and destroy the already-established channel via\nl2cap_chan_del(chan, ECONNRESET).\n\nClear chan->ident for all matching channels on success, and harden the\nfailure path by using l2cap_chan_hold_unless_zero() consistent with\nother L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bug is reached by sending crafted L2CAP ECRED reconfiguration responses over an established Bluetooth Low Energy ACL connection (HCI ACL → L2CAP LE signaling channel), which requires proximity on the same Bluetooth radio segment.\nAC:L - Once a BLE ECRED session exists, the remote peer fully controls signaling traffic and can reliably complete a reconfiguration handshake and then replay a failure response with the stale identifier; no special victim state or memory layout is required beyond an active connection.\nPR:N - Exploitation requires only the ability to act as a remote Bluetooth peer sending L2CAP signaling packets; no local shell access, capabilities, or root privileges on the victim host are needed.\nUI:N - No victim user action beyond having Bluetooth enabled and an attacker-established BLE connection is required; the attacker can inject the malicious L2CAP_ECRED_RECONF_RSP frames programmatically without user interaction.\nS:U - The impact is confined to the kernel Bluetooth/L2CAP security authority on the victim host and does not cross a VM, sandbox, or IOMMU boundary.\nC:H - The uncleorrected failure path used unsafe refcounting on matched channels, and stale-identifier matching during concurrent teardown can produce use-after-free conditions that are exploitable for kernel memory disclosure. The uncorrected failure path used unsafe refcounting on matched channels, and stale-identifier matching during concurrent teardown can produce use-after-free conditions that are exploitable for kernel memory disclosure.\nI:H - Erroneous `l2cap_chan_del()` on live channels corrupts kernel connection state, and the associated refcount/UAF race on the failure path can be leveraged for heap manipulation and potential arbitrary kernel write or code execution.\nA:H - A remote attacker can repeatedly force teardown of established ECRED L2CAP channels (denying Bluetooth services on phones, automotive, IoT, and embedded systems), and the underlying refcount bug can also trigger kernel crashes."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_core.c"],"versions":[{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"59f5ecf6ad5c4db6ae81965a96156954a3b0d89a","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"ae0152d77d101c920769934fb102b18de0c6f526","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"c2afd2613fda90107c5e2fe8e855627451749c78","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"cc2b4f749de09975bfa06e58bbbad2f6acd4c79c","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"3b5b5f423b4fd23404a393bda8adba3cd6f74ef1","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"f39049304ba655ffcbb92edbdf8c51a1f1210bed","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"8e7977afaef37c6bd2b2654f1bce6ab40d471147","status":"affected","versionType":"git"},{"version":"15f02b91056253e8cdc592888f431da0731337b8","lessThan":"00e1950716c6ed67d74777b2db286b0fa23b4be9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_core.c"],"versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","status":"unaffected","versionType":"semver"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"5.10.259"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.12.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.18.35"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.0.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/59f5ecf6ad5c4db6ae81965a96156954a3b0d89a"},{"url":"https://git.kernel.org/stable/c/ae0152d77d101c920769934fb102b18de0c6f526"},{"url":"https://git.kernel.org/stable/c/c2afd2613fda90107c5e2fe8e855627451749c78"},{"url":"https://git.kernel.org/stable/c/cc2b4f749de09975bfa06e58bbbad2f6acd4c79c"},{"url":"https://git.kernel.org/stable/c/3b5b5f423b4fd23404a393bda8adba3cd6f74ef1"},{"url":"https://git.kernel.org/stable/c/f39049304ba655ffcbb92edbdf8c51a1f1210bed"},{"url":"https://git.kernel.org/stable/c/8e7977afaef37c6bd2b2654f1bce6ab40d471147"},{"url":"https://git.kernel.org/stable/c/00e1950716c6ed67d74777b2db286b0fa23b4be9"}],"title":"Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success","x_generator":{"engine":"bippy-1.2.0"}}}}