---
id: CVE-2026-98247
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_codec: validate vendor codec count length

  The Read Local Supported Codecs parsers consume the variable-sized
  standard codec array before parsing the ven…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_codec: validate vendor codec count length

  The Read Local Supported Codecs parsers consume the variable-sized
  standard codec array before parsing the ven…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    a6da782fefae611e68a1aa79644065fc8ca5abcd
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    e4cfd3c4299105237458b27958bd7b0aa4c60795
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    f49a543d76d48f184b34225d9c0e2fc4cbdea8ec
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    12a82819b0cada6e304790b1097f8f9006eb6123
  - >-
    Linux >= 8961987f3f5fa2f2618e72304d013c8dd5e604a6 <
    d0795cfd6f655f4de84868a4f4bb41a03f037b3d
  - Linux 5.16
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:12.940'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98247'
references:
  - url: 'https://git.kernel.org/stable/c/12a82819b0cada6e304790b1097f8f9006eb6123'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9c04b9a4d08b95dee901d24b7607c4cbd65fa0a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a6da782fefae611e68a1aa79644065fc8ca5abcd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d0795cfd6f655f4de84868a4f4bb41a03f037b3d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4cfd3c4299105237458b27958bd7b0aa4c60795'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f49a543d76d48f184b34225d9c0e2fc4cbdea8ec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.431Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_codec: validate vendor codec count length

The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count.  Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.

If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data.  Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
