CVE-2026-53254
Bluetooth: RFCOMM: validate skb length in MCC handlers
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
25 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: validate skb length in MCC handlers
The RFCOMM MCC handlers cast skb->data to protocol-specific structs
without validating skb->len first. A malicious remote device can send
truncated MCC frames and trigger out-of-bounds reads in these handlers.
Fix this by using skb_pull_data() to validate and access the required
data before dereferencing it.
rfcomm_recv_rpn() requires special handling since ETSI TS 07.10 allows
1-byte RPN requests. Handle this by validating only the DLCI byte first,
and validating the full struct only when len > 1.
Productos afectados
Linux · Linux¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://git.kernel.org/stable/c/08b9c1fbe78f4ad3f6250c6541cfaabdbeb81997https://git.kernel.org/stable/c/0d637136ce89f9a2309b2c3502402ce400dab0efhttps://git.kernel.org/stable/c/1b070ac9e99c2c2c3a8112943ca98ab6fca7f10chttps://git.kernel.org/stable/c/23882b828c3c8c51d0c946446a396b10abb3b16bhttps://git.kernel.org/stable/c/3eabc6d47a0ad22b053329997aaf0ec1e581e392https://git.kernel.org/stable/c/7c15c7c2878957cbfed93bcc29c13fdace464254https://git.kernel.org/stable/c/98377e6b1a1a56561ec66a181573ea2b61b2079e