Impact
The vulnerability lies in the Linux kernel's Bluetooth RFCOMM implementation, where the function rfcomm_apply_pn() accepts a zero MTU value from a remote peer without validation. When an MTU of zero is negotiated, the sendmsg path enters an infinite loop because each fragment size becomes zero, causing continuous allocation of zero-length skbs and exhausting system memory. This leads to a denial‑of‑service condition where the system can become unresponsive or crash.
Affected Systems
The affected product is the Linux kernel, specifically the RFCOMM module that handles Bluetooth connections. Vendor information lists Linux: Linux and no specific kernel versions are identified, so all Linux kernel builds that include the unpatched RFCOMM code are potentially vulnerable. Users of any distribution running a kernel version prior to the patch commit should assess whether they are impacted.
Risk and Exploitability
The exploitation probability is indicated as below 1% by EPSS, and the vulnerability is not listed in CISA KEV, suggesting it is not actively exploited yet. However, because the flaw allows remote code to trigger a memory exhaustion attack via a simple RFCOMM frame, the risk to availability is significant for systems with Bluetooth enabled. The lack of a known CVSS score in the data limits precise severity assessment, but the impact of exhausting memory makes this a high‑risk denial of service scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA