{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89569","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.726Z","datePublished":"2026-09-11T19:44:38.838Z","dateUpdated":"2026-09-14T12:01:05.429Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:05.429Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: serialize security confirmation handling\n\nrfcomm_security_cfm() looks up a session on session_list and then walks\nits DLC list without holding rfcomm_mutex. Since RFCOMM session teardown\nuses rfcomm_mutex, krfcommd can close and free the same session and DLCs\nconcurrently:\n\n  hci_rx_work                    krfcommd\n  -----------                    ---------\n  rfcomm_session_get()\n                                 rfcomm_lock()\n                                 rfcomm_session_close()\n                                   rfcomm_dlc_unlink()\n                                   rfcomm_session_del()\n                                     kfree(s)\n                                 rfcomm_unlock()\n  walk s->dlcs\n\nThe callback can then read a freed session list head and touch freed DLCs\nwhile updating their flags or timers.\n\nSerialize the session lookup and DLC traversal in rfcomm_security_cfm()\nwith rfcomm_mutex. This matches the existing RFCOMM session lifetime\nrules and prevents concurrent rfcomm_session_del() / rfcomm_dlc_unlink()\nfrom tearing the objects down while the callback is using them.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in rfcomm_security_cfm+0x41c/0x440\n  Read of size 8 at addr ffff888111fb3960 by task kworker/u17:1/89\n  Workqueue: hci0 hci_rx_work\n  Call Trace:\n   rfcomm_security_cfm+0x41c/0x440\n   hci_encrypt_cfm+0x139/0x590\n   hci_encrypt_change_evt+0x37b/0xc40\n   hci_event_packet+0x71b/0xb20\n   hci_rx_work+0x293/0x730\n  Allocated by task 69:\n   rfcomm_session_add+0x9e/0x2f0\n   rfcomm_run+0x44b/0x41e0\n  Freed by task 69:\n   kfree+0x131/0x3c0\n   rfcomm_session_del+0x188/0x220\n   rfcomm_run+0x1985/0x41e0"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - rfcomm_security_cfm() runs from hci_encrypt_cfm()/hci_auth_cfm() on hci_rx_work when the controller reports encryption or authentication complete. An in-range Bluetooth peer that opens an RFCOMM/L2CAP session can drive those HCI events; kernel CNA guidance scores Bluetooth as Adjacent.\nAC:L - The UAF is a race between hci_rx_work walking the session and krfcommd freeing it. A peer controls both sides by triggering encrypt/auth complete while disconnecting RFCOMM/L2CAP or the ACL link so krfcommd runs rfcomm_session_close(), and can retry until the window is hit.\nPR:N - A nearby Bluetooth device needs no Linux account or capability. krfcommd listens on L2CAP PSM RFCOMM at default BT_SECURITY_LOW, and HCI encrypt/auth complete (including failures) call rfcomm_security_cfm() with no local credential check.\nUI:N - Phones, cars, and IoT devices with Bluetooth enabled accept RFCOMM/L2CAP and emit encrypt-change events during ordinary link setup or teardown. No extra victim action such as pairing confirmation, mounting, or opening a file is required at exploit time.\nS:U - The UAF corrupts kernel RFCOMM session and DLC objects in the host Bluetooth stack. It does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - After rfcomm_session_del() frees the session, the callback reads the slab-freed list head and DLC flags, state, and sec_level. Kernel UAF of these objects enables heap reuse and arbitrary kernel read primitives.\nI:H - The callback writes DLC flag bits and arms or cancels DLC timers on objects krfcommd may already have unlinked and freed, so a reused slab object can be corrupted or have its timer hijacked for control-flow takeover.\nA:H - KASAN reported slab-use-after-free in rfcomm_security_cfm() on hci_rx_work; triggering the race oopses or panics the kernel even without a full exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/rfcomm/core.c"],"versions":[{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"62ce8b33eb238cf18c15207332fbdc26d858f592","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"3873f3449701b3dc98cba577923be6493598e7a1","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"7ded3264106418c6456ccceaafd9fda596ce12c3","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"82425b14f0fb22e46cfddc56d6465570f5ed0ce6","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"1b7841ffad08e911e8c4b9470f3fa08423568940","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"946d76db77ee5f922968ce558629ae47b381e3fc","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"fbf7961964a6e93360179f64712320ae9a1e9577","status":"affected","versionType":"git"},{"version":"08c30aca9e698faddebd34f81e1196295f9dc063","lessThan":"759c185d0bbdb131357408f50b8735e04ed3caff","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/rfcomm/core.c"],"versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/62ce8b33eb238cf18c15207332fbdc26d858f592"},{"url":"https://git.kernel.org/stable/c/3873f3449701b3dc98cba577923be6493598e7a1"},{"url":"https://git.kernel.org/stable/c/7ded3264106418c6456ccceaafd9fda596ce12c3"},{"url":"https://git.kernel.org/stable/c/82425b14f0fb22e46cfddc56d6465570f5ed0ce6"},{"url":"https://git.kernel.org/stable/c/1b7841ffad08e911e8c4b9470f3fa08423568940"},{"url":"https://git.kernel.org/stable/c/946d76db77ee5f922968ce558629ae47b381e3fc"},{"url":"https://git.kernel.org/stable/c/fbf7961964a6e93360179f64712320ae9a1e9577"},{"url":"https://git.kernel.org/stable/c/759c185d0bbdb131357408f50b8735e04ed3caff"}],"title":"Bluetooth: RFCOMM: serialize security confirmation handling","x_generator":{"engine":"bippy-1.2.0"}}}}