{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-52918","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.367Z","datePublished":"2026-06-24T07:14:14.539Z","dateUpdated":"2026-08-05T12:31:40.163Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:31:40.163Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: serialize accept_q access\n\nbt_sock_poll() walks the accept queue without synchronization, while\nchild teardown can unlink the same socket and drop its last reference.\nThe unsynchronized accept queue walk has existed since the initial\nBluetooth import.\n\nProtect accept_q with a dedicated lock for queue updates and polling.\nAlso rework bt_accept_dequeue() to take temporary child references under\nthe queue lock before dropping it and locking the child socket."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The vulnerable accept queue is in the Bluetooth socket stack and is reachable through nearby Bluetooth peers opening and tearing down L2CAP/RFCOMM-style connections to a listening Bluetooth service.\nAC:L - The race can be exercised repeatedly by driving connection and disconnection activity while the listener polls/accepts, and no rare kernel configuration or condition outside the attacker’s reasonable influence is required.\nPR:N - An adjacent Bluetooth peer can reach the incoming connection and teardown paths without local system privileges or prior authenticated application access in low-security/default Bluetooth service scenarios.\nUI:N - No victim user action is required once the Bluetooth service/socket is listening; the attacker can initiate the relevant Bluetooth protocol traffic.\nS:U - The bug affects kernel Bluetooth socket state within the same host security authority and does not cross a VM, IOMMU, or similar security boundary.\nC:H - The bug is a use-after-free/unsynchronized traversal of freed socket objects; under the required conservative scoring rule, UAF exposure is treated as potentially enabling high-impact kernel information disclosure.\nI:H - The fixed code also pins children during dequeue to prevent references to freed objects, and UAF/refcount operations on reclaimed kernel memory are conservatively treated as potentially enabling memory corruption or control-flow compromise.\nA:H - A failed race or invalid traversal can dereference freed or attacker-influenced kernel memory, producing a kernel oops/panic or repeated Bluetooth service/kernel disruption."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/bluetooth.h","net/bluetooth/af_bluetooth.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d9ce4de05df2385c19e2c7d12f529144e1a44af1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"41c8c1c7923e86e0eb59cfb4279349112756a336","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4ec17782fd186f901a7329605d11048b085b945a","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"be43e6b4043113c3b3cf887c3c8350f67140274c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"85f8674cae82053f1e6bab295f6a8422cca14db5","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8b4c412e001b0c670eb937beab491af974da55b3","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a218bf69eb51fefe59a3976fa8925261141f681c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e83f5e24da741fa9405aeeff00b08c5ee7c37b88","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/bluetooth.h","net/bluetooth/af_bluetooth.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.259"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d9ce4de05df2385c19e2c7d12f529144e1a44af1"},{"url":"https://git.kernel.org/stable/c/41c8c1c7923e86e0eb59cfb4279349112756a336"},{"url":"https://git.kernel.org/stable/c/4ec17782fd186f901a7329605d11048b085b945a"},{"url":"https://git.kernel.org/stable/c/be43e6b4043113c3b3cf887c3c8350f67140274c"},{"url":"https://git.kernel.org/stable/c/85f8674cae82053f1e6bab295f6a8422cca14db5"},{"url":"https://git.kernel.org/stable/c/8b4c412e001b0c670eb937beab491af974da55b3"},{"url":"https://git.kernel.org/stable/c/a218bf69eb51fefe59a3976fa8925261141f681c"},{"url":"https://git.kernel.org/stable/c/e83f5e24da741fa9405aeeff00b08c5ee7c37b88"}],"title":"Bluetooth: serialize accept_q access","x_generator":{"engine":"bippy-1.2.0"}}}}