← All Advisories

CVE-2026-93783

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93783

Key Details

CVECVE-2026-93783
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame

rfcomm_recv_frame() casts skb->data to struct rfcomm_hdr and dereferences

hdr->addr and hdr->ctrl without validating skb->len first. A truncated

frame with skb->len less than the minimum header size causes an

out-of-bounds read of uninitialized memory. Additionally, a zero-length

frame causes skb->len-- to underflow to UINT_MAX, making

skb_tail_pointer() read far past the buffer.

Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC

handlers") fixed the same class of missing-length-check bugs in the MCC

sub-handlers, but the top-level rfcomm_recv_frame() was left unfixed.

KMSAN reports:

BUG: KMSAN: uninit-value in rfcomm_run

...

Uninit was created at:

__alloc_skb+0x474/0xb60

vhci_write+0xe9/0x870

Fix this by rejecting frames smaller than sizeof(struct rfcomm_hdr) + 1

(the minimum frame must have a 3-byte header and a 1-byte FCS). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93783
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93783