Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: access chan->conn safely in get/setsockopt

Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref")
l2cap_chan::conn has held reference and remains non-NULL also after the
corresponding hci_conn is deleted. In this state accessing various
fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in
l2cap_sock_setsockopt() access of conn->hcon->hdev.

Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before
trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in
getsockopt/setsockopt to ensure it stays alive, and to avoid data races
in l2cap_chan fields.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel Bluetooth L2CAP implementation a use‑after‑free occurs when the channel’s hci_conn is deleted but the l2cap_chan::conn reference remains. Accessing fields such as hci_conn::hdev in l2cap_sock_setsockopt triggers a KASAN crash that results in a kernel panic, effectively denying availability. The flaw provides no remote code execution or privilege escalation; it only causes service disruption for the local system. Based on the description, it is inferred that the kernel crash is caused by dereferencing a dangling pointer after the associated hci_conn has been freed.

Affected Systems

The vulnerability is tied to Linux kernel builds lacking commit b66774b48dd9 that introduced reference counting and locking for L2CAP channels. Devices running older kernels with Bluetooth L2CAP support—such as desktops, servers, mobile devices, and embedded systems—are at risk. The issue is vendor specific to the Linux kernel. It is inferred that any system with an exposed Bluetooth stack using the affected L2CAP code could trigger this crash.

Risk and Exploitability

The CVSS score of 7.8 indicates a medium‑to‑high severity but the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV and cannot be triggered remotely; it requires local interaction with the Bluetooth subsystem, such as an attacker who can invoke setsockopt on a L2CAP socket. Because it only causes a denial of service without elevating privileges, the overall risk is that a compromised or malicious local user could destabilize the system, but it does not present a broader enterprise threat. This assessment is based on the information provided in the CVE description.

Generated by OpenCVE AI on September 20, 2026 at 04:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the system’s Linux kernel to a release that incorporates commit b66774b48dd9, which safely references the connection in L2CAP channel handling.
  • If an immediate kernel update cannot be performed, stop or disable the Bluetooth service (for example, systemctl disable bluetooth) to avoid triggering setsockopt on L2CAP sockets until the patch is applied.
  • Check system logs for KASAN messages to identify accidental trigger of the vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in l2cap_sock_setsockopt() access of conn->hcon->hdev. Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in getsockopt/setsockopt to ensure it stays alive, and to avoid data races in l2cap_chan fields.
Title Bluetooth: L2CAP: access chan->conn safely in get/setsockopt
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:59.418Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:00.900

Modified: 2026-09-18T18:17:41.697

Link: CVE-2026-90093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses