{"id":"CVE-2026-98247","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the ven…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the ven…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < 9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8","Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < a6da782fefae611e68a1aa79644065fc8ca5abcd","Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < e4cfd3c4299105237458b27958bd7b0aa4c60795","Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < f49a543d76d48f184b34225d9c0e2fc4cbdea8ec","Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < 12a82819b0cada6e304790b1097f8f9006eb6123","Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 < d0795cfd6f655f4de84868a4f4bb41a03f037b3d","Linux 5.16"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:12.940","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98247","references":[{"url":"https://git.kernel.org/stable/c/12a82819b0cada6e304790b1097f8f9006eb6123","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6da782fefae611e68a1aa79644065fc8ca5abcd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0795cfd6f655f4de84868a4f4bb41a03f037b3d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4cfd3c4299105237458b27958bd7b0aa4c60795","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f49a543d76d48f184b34225d9c0e2fc4cbdea8ec","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.431Z","slug":"CVE-2026-98247","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the vendor codec count.  Although the\ninitial reply-size check includes a vendor count byte in the fixed layout,\nit does not guarantee that the byte remains after the standard codec array.\n\nIf a controller reply ends immediately after that array, calculating the\nvendor codec array size reads vnd_codecs->num beyond the skb data.  Use\nskb_pull_data() to validate and consume each codec header before using its\ncount in both command variants.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}