{"schema_version":"1.9.0","id":"CVE-2026-63976","published":"2026-07-19T14:56:01.284Z","modified":"2026-08-31T18:26:04.217946450Z","related":["SUSE-SU-2026:23066-1","SUSE-SU-2026:23068-1","SUSE-SU-2026:23193-1","SUSE-SU-2026:23194-1","SUSE-SU-2026:23221-1","SUSE-SU-2026:23231-1","SUSE-SU-2026:23237-1","SUSE-SU-2026:23241-1","SUSE-SU-2026:23244-1","SUSE-SU-2026:3790-1","SUSE-SU-2026:3810-1","openSUSE-SU-2026:21555-1"],"summary":"Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: clear chan->ident on ECRED reconfiguration success\n\nl2cap_ecred_reconf_rsp() returns early on success without clearing\nchan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp,\nl2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a\nsuccessful transaction to prevent the channel from matching subsequent\nresponses with the recycled ident value.\n\nA remote attacker that completed a reconfiguration as the peer can\nreplay a failure response with the stale ident, causing the kernel to\nmatch and destroy the already-established channel via\nl2cap_chan_del(chan, ECONNRESET).\n\nClear chan->ident for all matching channels on success, and harden the\nfailure path by using l2cap_chan_hold_unless_zero() consistent with\nother L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident).","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"15f02b91056253e8cdc592888f431da0731337b8"},{"fixed":"59f5ecf6ad5c4db6ae81965a96156954a3b0d89a"},{"fixed":"ae0152d77d101c920769934fb102b18de0c6f526"},{"fixed":"c2afd2613fda90107c5e2fe8e855627451749c78"},{"fixed":"cc2b4f749de09975bfa06e58bbbad2f6acd4c79c"},{"fixed":"3b5b5f423b4fd23404a393bda8adba3cd6f74ef1"},{"fixed":"f39049304ba655ffcbb92edbdf8c51a1f1210bed"},{"fixed":"8e7977afaef37c6bd2b2654f1bce6ab40d471147"},{"fixed":"00e1950716c6ed67d74777b2db286b0fa23b4be9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63976.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63976.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/00e1950716c6ed67d74777b2db286b0fa23b4be9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3b5b5f423b4fd23404a393bda8adba3cd6f74ef1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/59f5ecf6ad5c4db6ae81965a96156954a3b0d89a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8e7977afaef37c6bd2b2654f1bce6ab40d471147"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae0152d77d101c920769934fb102b18de0c6f526"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c2afd2613fda90107c5e2fe8e855627451749c78"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cc2b4f749de09975bfa06e58bbbad2f6acd4c79c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f39049304ba655ffcbb92edbdf8c51a1f1210bed"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63976.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63976"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63976.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}