{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53358","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.400Z","datePublished":"2026-07-02T13:43:17.630Z","dateUpdated":"2026-08-05T12:35:07.724Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:35:07.724Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: use chan timer to close channels in cleanup_listen()\n\nl2cap_chan_close() removes the channel from conn->chan_l, which\nmust be done under conn->lock.  cleanup_listen() runs under the\nparent sk_lock, so acquiring conn->lock would invert the\nestablished conn->lock -> chan->lock -> sk_lock order.\n\nInstead of calling l2cap_chan_close() directly, schedule\nl2cap_chan_timeout with delay 0 to close the channel\nasynchronously.  The timeout handler already acquires conn->lock\nand chan->lock in the correct order.\n\nThe timer is only armed when chan->conn is still set: if it is\nalready NULL, l2cap_conn_del() has already processed this channel\n(l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb),\nso there is nothing left to do.  If l2cap_conn_del() races in\nafter the timer is armed, __clear_chan_timer() inside\nl2cap_chan_del() cancels it; if the timer has already fired, the\nhandler returns harmlessly because chan->conn was cleared."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The vulnerable L2CAP child channels are created and torn down through Bluetooth BR/EDR or LE signaling from a nearby peer, so the remote reachability is adjacent. Bluetooth is not generally Internet-routable, but phones, embedded devices, and kiosks commonly expose this surface to nearby attackers.\nAC:L - The bug is a race, but the attacker can repeatedly create queued L2CAP children and trigger disconnect/cleanup timing; related reports show the listen/close versus HCI-disconnect race reproducing reliably. Under the required rule, the attacker-controlled repeatable race is scored Low complexity.\nPR:N - A nearby Bluetooth peer can reach L2CAP connection setup before application authentication, including low-security/SDP-style services, without an OS account on the target. If a local service lifecycle participates in cleanup, that is target state rather than attacker privilege.\nUI:N - No victim user action such as opening a file or accepting a prompt is required once Bluetooth and a listening L2CAP service are present. The attacker can drive the Bluetooth connection and disconnect attempts directly.\nS:U - The corruption occurs inside the Linux kernel Bluetooth stack and impacts the same kernel security authority. There is no VM escape, IOMMU bypass, or cross-authority boundary change indicated.\nC:H - The old path called l2cap_chan_close() without conn->lock, allowing unlocked removal from conn->chan_l and races with l2cap_conn_del() over sock/l2cap_chan lifetime. This is kernel memory corruption/UAF-adjacent behavior, which is defensibly exploitable for high confidentiality impact.\nI:H - The race can corrupt kernel list/refcount state around l2cap_chan and sock teardown, giving a plausible route to use-after-free style heap manipulation. Kernel memory corruption is scored as high integrity impact under the provided guidance.\nA:H - At minimum, racing channel cleanup and connection deletion can cause list corruption, double teardown, UAF, KASAN splats, oops, or panic. A repeatable kernel crash is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_sock.c"],"versions":[{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"3634cbdc2eb414b69ffa752ddbe5e0458518e321","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"e1c100e2d61bd8c718b7d91fe3e050780a9bf72d","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"89dec92041717b027216e110599e4f6d6c921b79","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"50dfec218808b148ab4247b1858031b7a32015c5","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"859d3ace791ed878ae9ba5522c7844d960da8f88","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"7555fd885a0603f50e49a655850a1f2bd8a25398","status":"affected","versionType":"git"},{"version":"3df91ea20e744344100b10ae69a17211fcf5b207","lessThan":"8c8e620467a7b51562dbcefbd1f09f288d7d710d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_sock.c"],"versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","status":"unaffected","versionType":"semver"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"5.10.259"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"6.12.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"6.18.35"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"7.0.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3634cbdc2eb414b69ffa752ddbe5e0458518e321"},{"url":"https://git.kernel.org/stable/c/e1c100e2d61bd8c718b7d91fe3e050780a9bf72d"},{"url":"https://git.kernel.org/stable/c/deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9"},{"url":"https://git.kernel.org/stable/c/89dec92041717b027216e110599e4f6d6c921b79"},{"url":"https://git.kernel.org/stable/c/50dfec218808b148ab4247b1858031b7a32015c5"},{"url":"https://git.kernel.org/stable/c/859d3ace791ed878ae9ba5522c7844d960da8f88"},{"url":"https://git.kernel.org/stable/c/7555fd885a0603f50e49a655850a1f2bd8a25398"},{"url":"https://git.kernel.org/stable/c/8c8e620467a7b51562dbcefbd1f09f288d7d710d"}],"title":"Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()","x_generator":{"engine":"bippy-1.2.0"}}}}