← Back to CVE search

CVE-2026-0095

Bluetooth

Description

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS 8EPSS 0.107%Risk 0.81
View source
Published
2026-06-01 22:16:23
Affected versions
unknown
Type
Core software
Last modified
2026-07-22 17:10:00
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H