<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 18:23:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-64127 — Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-64127</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer&lt;/p&gt;
&lt;p&gt;Commit 1c08108f3014 (&amp;#34;Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end
warnings&amp;#34;) converted the on-stack request PDU in l2cap_ecred_reconfigure()
from an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the
size and source-pointer arguments to l2cap_send_cmd():&lt;/p&gt;
&lt;p&gt;-    struct {
  -            struct l2cap_ecred_reconf_req req;
  -            __le16 scid;
  -    } pdu;
  +    DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);
       ...
       l2cap_send_cmd(conn, chan-&amp;gt;ident, L2CAP_ECRED_RECONF_REQ,
                      sizeof(pdu), &amp;amp;pdu);&lt;/p&gt;
&lt;p&gt;After the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous
union pdu_u plus a local pointer &amp;#34;pdu&amp;#34; pointing at it. Therefore:&lt;/p&gt;
&lt;p&gt;- sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on
    64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).
  - &amp;amp;pdu is the address of the local pointer&amp;#39;s stack storage, not the
    address of the request payload.&lt;/p&gt;
&lt;p&gt;l2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls
skb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet
body therefore contains 8 bytes copied from the kernel stack starting at
&amp;amp;pdu -- the 8 bytes overlap the pdu pointer&amp;#39;s value, leaking a kernel
stack address to the paired Bluetooth peer. The intended (mtu, mps, scid)
fields are not transmitted at all…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer&lt;/p&gt;
&lt;p&gt;Commit 1c08108f3014 (&amp;#34;Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end
warnings&amp;#34;) converted the on-stack request PDU in l2cap_ecred_reconfigure()
from an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the
size and source-pointer arguments to l2cap_send_cmd():&lt;/p&gt;
&lt;p&gt;-    struct {
  -            struct l2cap_ecred_reconf_req req;
  -            __le16 scid;
  -    } pdu;
  +    DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);
       ...
       l2cap_send_cmd(conn, chan-&amp;gt;ident, L2CAP_ECRED_RECONF_REQ,
                      sizeof(pdu), &amp;amp;pdu);&lt;/p&gt;
&lt;p&gt;After the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous
union pdu_u plus a local pointer &amp;#34;pdu&amp;#34; pointing at it. Therefore:&lt;/p&gt;
&lt;p&gt;- sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on
    64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).
  - &amp;amp;pdu is the address of the local pointer&amp;#39;s stack storage, not the
    address of the request payload.&lt;/p&gt;
&lt;p&gt;l2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls
skb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet
body therefore contains 8 bytes copied from the kernel stack starting at
&amp;amp;pdu -- the 8 bytes overlap the pdu pointer&amp;#39;s value, leaking a kernel
stack address to the paired Bluetooth peer. The intended (mtu, mps, scid)
fields are not transmitted at all…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-64127</guid>
    </item>
  </channel>
</rss>
