CVE-2026-90256
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
hci_conn::l2cap_data is accessed without locks in l2cap_disconn_ind via hci_conn_timeout (disc_work) -> hci_proto_disconn_ind -> l2cap_disconn_ind. This is UAF if the l2cap_conn is deleted concurrently.
disc_work is disabled sync in hci_conn_del(), so we cannot take hci_dev_lock in disc_work.
Fix by using proto_lock to guard l2cap_data, in addition to hdev->lock which is held in other access paths.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ab4eedb790cae44313759b50fe47da285e2519d5 < b495a3a9b33bc4e4613e685bf5c96c136caa22d8 | affected |
| Linux | Linux | ab4eedb790cae44313759b50fe47da285e2519d5 < 2b66c83ff1751d6bd3201b3017206262ab46dc05 | affected |
| Linux | Linux | efc30877bd4bc85fefe98d80af60fafc86e5775e | affected |
| Linux | Linux | f87271d21dd4ee83857ca11b94e7b4952749bbae | affected |
| Linux | Linux | 18ab6b6078fa8191ca30a3065d57bf35d5635761 | affected |
| Linux | Linux | 6.6.84 < 6.7 | affected |
| Linux | Linux | 6.12.20 < 6.13 | affected |
| Linux | Linux | 6.13.8 < 6.14 | affected |
| Linux | Linux | 6.14 | affected |
| Linux | Linux | 0 < 6.14 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/b495a3a9b33bc4e4613e685bf5c96c136caa22d8
- https://git.kernel.org/stable/c/2b66c83ff1751d6bd3201b3017206262ab46dc05
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.