Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop

rfcomm_apply_pn() accepts the MTU value from a remote PN (Parameter
Negotiation) frame without checking for zero. When the remote peer
sends an MTU of zero, d->mtu is set to 0. This causes the sendmsg
path to enter an infinite loop when fragmenting data, as each fragment
has size == min_t(size_t, len, 0) == 0, so the remaining length never
decreases. The infinite allocation of zero-length skbs exhausts all
system memory.

Fix by clamping d->mtu to RFCOMM_DEFAULT_MTU when the negotiated
value is zero, consistent with the initial value assigned in
rfcomm_dlc_alloc().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability lies in the Linux kernel's Bluetooth RFCOMM implementation, where the function rfcomm_apply_pn() accepts a zero MTU value from a remote peer without validation. When an MTU of zero is negotiated, the sendmsg path enters an infinite loop because each fragment size becomes zero, causing continuous allocation of zero-length skbs and exhausting system memory. This leads to a denial‑of‑service condition where the system can become unresponsive or crash.

Affected Systems

The affected product is the Linux kernel, specifically the RFCOMM module that handles Bluetooth connections. Vendor information lists Linux: Linux and no specific kernel versions are identified, so all Linux kernel builds that include the unpatched RFCOMM code are potentially vulnerable. Users of any distribution running a kernel version prior to the patch commit should assess whether they are impacted.

Risk and Exploitability

The exploitation probability is indicated as below 1% by EPSS, and the vulnerability is not listed in CISA KEV, suggesting it is not actively exploited yet. However, because the flaw allows remote code to trigger a memory exhaustion attack via a simple RFCOMM frame, the risk to availability is significant for systems with Bluetooth enabled. The lack of a known CVSS score in the data limits precise severity assessment, but the impact of exhausting memory makes this a high‑risk denial of service scenario.

Generated by OpenCVE AI on September 20, 2026 at 03:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that clamps the MTU to RFCOMM_DEFAULT_MTU when zero is negotiated.
  • Disable the Bluetooth subsystem if not required on the system.
  • Update all Linux kernels to the latest release ensuring the RFCOMM fix is included.

Generated by OpenCVE AI on September 20, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop rfcomm_apply_pn() accepts the MTU value from a remote PN (Parameter Negotiation) frame without checking for zero. When the remote peer sends an MTU of zero, d->mtu is set to 0. This causes the sendmsg path to enter an infinite loop when fragmenting data, as each fragment has size == min_t(size_t, len, 0) == 0, so the remaining length never decreases. The infinite allocation of zero-length skbs exhausts all system memory. Fix by clamping d->mtu to RFCOMM_DEFAULT_MTU when the negotiated value is zero, consistent with the initial value assigned in rfcomm_dlc_alloc().
Title Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:03.527Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90088

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:59.880

Modified: 2026-09-17T17:16:59.880

Link: CVE-2026-90088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-20

    Improper Input Validation