{"id":"AZL-106200","summary":"CVE-2026-98247 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the vendor codec count.  Although the\ninitial reply-size check includes a vendor count byte in the fixed layout,\nit does not guarantee that the byte remains after the standard codec array.\n\nIf a controller reply ends immediately after that array, calculating the\nvendor codec array size reads vnd_codecs-\u003enum beyond the skb data.  Use\nskb_pull_data() to validate and consume each codec header before using its\ncount in both command variants.","modified":"2026-10-07T14:16:59.014284590Z","published":"2026-10-06T09:18:12Z","upstream":["CVE-2026-98247"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98247"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106200.json"}}],"schema_version":"1.9.0"}