Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN

New sk should not be added to parent socket accept queue after last
l2cap_sock_cleanup_listen() has run in l2cap_sock_teardown_cb() and
state set to BT_CLOSED, as that can result to UAF on dereferencing the
dangling parent reference.

l2cap_sock_new_connection_cb() may race with parent l2cap_chan teardown,
due to chan->state accessed without consistent locking:

[Task 1] [Task 2]
l2cap_sock_release(parent) l2cap_connect
l2cap_sock_shutdown pchan = l2cap_global_chan_by_psm
l2cap_chan_lock(pchan)
l2cap_chan_close
l2cap_sock_teardown_cb
pchan->state = BT_CLOSED
l2cap_chan_unlock(pchan) ------> l2cap_chan_lock(pchan)
l2cap_new_connection
l2cap_sock_new_connection_cb
l2cap_chan_lock(pchan) <-------- l2cap_chan_unlock(pchan)
l2cap_sock_kill(parent) /* bt_sk(sk)->parent dangling */

Fix by adding check for sk_state == BT_LISTEN after acquiring sk lock in
l2cap_sock_new_connection_cb(). Add lock_sock() around sk_state writes
where missing, to avoid data races.

Although the data races on pchan->state should be fixed too, this
defensive sk_state check probably makes sense in any case.
Published: 2026-09-17
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that can lead to a crash or privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw comes from a race condition in the Linux kernel’s Bluetooth L2CAP implementation. When a listening socket is torn down, a concurrent attempt to add a new accept queue entry may reference a parent socket that has already been freed. This leads to a use‑after‑free in kernel space, which an attacker could exploit to cause a kernel crash or gain elevated privileges if they can trigger the race. The vulnerability exploits a lack of proper locking around the socket state and the parent reference, making the kernel’s memory safety dependent on timing.

Affected Systems

This issue affects the generic Linux kernel. No specific kernel release is listed, so any build that contains the unpatched Bluetooth L2CAP code may be vulnerable. The fix has been merged into the upstream source in the commits linked in the advisory, but systems running earlier kernels without that merge are at risk.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low likelihood of current exploitation, and the vulnerability is not recorded in the CISA KEV catalog. The CVSS score of 8 indicates high severity, aligning with the risk of kernel memory corruption. An attacker would need to orchestrate a timed race or manipulate an L2CAP client to trigger the fault, which could result in a denial‑of-service or privilege escalation. The overall risk remains low to moderate until a public exploit is found, but the severity of a successful exploit is substantial.

Generated by OpenCVE AI on September 20, 2026 at 05:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the patch that fixes the race condition and the use‑after‑free
  • Restart the system (or the affected services) so that the updated kernel code is loaded
  • If a kernel upgrade cannot be performed immediately, disable the Bluetooth service or block L2CAP connections until the patch is applied

Generated by OpenCVE AI on September 20, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN New sk should not be added to parent socket accept queue after last l2cap_sock_cleanup_listen() has run in l2cap_sock_teardown_cb() and state set to BT_CLOSED, as that can result to UAF on dereferencing the dangling parent reference. l2cap_sock_new_connection_cb() may race with parent l2cap_chan teardown, due to chan->state accessed without consistent locking: [Task 1] [Task 2] l2cap_sock_release(parent) l2cap_connect l2cap_sock_shutdown pchan = l2cap_global_chan_by_psm l2cap_chan_lock(pchan) l2cap_chan_close l2cap_sock_teardown_cb pchan->state = BT_CLOSED l2cap_chan_unlock(pchan) ------> l2cap_chan_lock(pchan) l2cap_new_connection l2cap_sock_new_connection_cb l2cap_chan_lock(pchan) <-------- l2cap_chan_unlock(pchan) l2cap_sock_kill(parent) /* bt_sk(sk)->parent dangling */ Fix by adding check for sk_state == BT_LISTEN after acquiring sk lock in l2cap_sock_new_connection_cb(). Add lock_sock() around sk_state writes where missing, to avoid data races. Although the data races on pchan->state should be fixed too, this defensive sk_state check probably makes sense in any case.
Title Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:58.080Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:00.757

Modified: 2026-09-18T18:17:41.517

Link: CVE-2026-90092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free