{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90091","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.786Z","datePublished":"2026-09-17T16:06:05.478Z","dateUpdated":"2026-09-18T17:52:56.765Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:52:56.765Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan\n\nFor L2CAP sockets without owning sk->sk_socket, reading\nl2cap_pi(sk)->chan may race against concurrent l2cap_sock_kill() ->\nl2cap_sock_put_chan().  This excludes simultaneous proto_ops callbacks,\nbut access in l2cap_sock_cleanup_listen() has unsafe lockless read.\n\n [Task 1]                         [Task 2 (hdev->workqueue)]\n l2cap_sock_release(parent)       l2cap_disconn_cfm\n   l2cap_sock_cleanup_listen        l2cap_conn_del\n     bt_accept_dequeue                l2cap_chan_del\n       lock_sock(sk)                    l2cap_sock_teardown_cb\n       bt_accept_unlink\n         bt_sk(sk)->parent = NULL\n       release_sock(sk) ----------------> lock_sock(sk)\n                                          parent = /* NULL */\n     lock_sock(sk) <--------------------- release_sock(sk)\n                                          sock_set_flag(sk, SOCK_ZAPPED)\n                                      l2cap_sock_close_cb\n                                        l2cap_sock_kill(sk)\n                                          l2cap_sock_put_chan\n     chan = READ l2cap_pi(sk)->chan         l2cap_pi(sk)->chan = NULL\n     l2cap_chan_hold_unless_zero            l2cap_put_chan(chan)\n       kref_get_unless_zero(&chan->ref)\n\nTask 1 may observe NULL which causes null-ptr-deref.\n\nFix the race by taking lock_sock() in l2cap_sock_kill() to\nsynchronize with l2cap_sock_cleanup_listen().  hold_unless_zero() is not\nneeded here, l2cap_pi(sk)->chan owns reference if it is non-NULL.\n\nClarify code comments vs. locking."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - A nearby peer's HCI Disconnection Complete (hci_disconn_complete_evt → hci_disconn_cfm → l2cap_disconn_cfm on hdev->rx_work) or L2CAP_DISCONN_REQ (l2cap_disconnect_req) runs l2cap_sock_put_chan on an unaccepted child created by L2CAP_CONN_REQ; the transport is Bluetooth radio range, so Adjacent not Network.\nAC:L - The attacker drives both sides: close() of their listening socket runs l2cap_sock_release → l2cap_sock_cleanup_listen → bt_accept_dequeue, while the peer's disconnect concurrently runs l2cap_sock_kill → l2cap_sock_put_chan on that child without lock_sock; repeating connect/disconnect/close hits the window.\nPR:L - l2cap_sock_create() allows unprivileged SOCK_SEQPACKET/SOCK_STREAM (only SOCK_RAW needs CAP_NET_RAW), and l2cap_validate_bredr_psm() permits dynamic PSM >= 0x1001 without CAP_NET_BIND_SERVICE, so listen()+close() needs only a normal local account; AF_BLUETOOTH is init_net-only (bt_sock_create), not a userns CAP_NET_ADMIN path.\nUI:N - The attacker closes their own listening L2CAP socket and, from a radio they control, sends L2CAP_CONN_REQ then disconnect; no other user must pair, accept, or confirm during the race.\nS:U - The race corrupts the host kernel l2cap_chan stored in l2cap_pi(sk)->chan of the unaccepted child; it does not escape a VM, bypass an IOMMU, or leave the kernel's own authority.\nC:H - cleanup_listen loads l2cap_pi(sk)->chan then calls l2cap_chan_hold_unless_zero(); concurrent l2cap_sock_put_chan plus l2cap_conn_del's final l2cap_chan_put can kfree that object first, so kref_get_unless_zero and later l2cap_chan_lock/__set_chan_timer run on a freed kmalloc l2cap_chan that can be sprayed for disclosure.\nI:H - Winning that UAF lets cleanup_listen take l2cap_chan_lock, arm __set_chan_timer, and l2cap_chan_put on a reclaimed fake chan, corrupting mutex/timer/kref state and invoking chan->ops from sprayed memory for hijack.\nA:H - If cleanup_listen observes the NULL stored by l2cap_sock_put_chan, l2cap_chan_hold_unless_zero() calls kref_get_unless_zero(&c->kref) with c==NULL and oopses; the UAF interleaving likewise panics on poisoned slab or a corrupted chan mutex."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/l2cap.h","net/bluetooth/l2cap_sock.c"],"versions":[{"version":"b39298044e5534612511a2ff5de03ba5f6e7a820","lessThan":"827de6bd2865b22aaabd554540def3b8a33018ab","status":"affected","versionType":"git"},{"version":"8c37e4338c801ebb8cee52436c01c41e009f6e87","lessThan":"7c7ac736b50fa259ed1bdddc18d79523f07c0442","status":"affected","versionType":"git"},{"version":"84e718b6a814edc84159361f9f454a4e92ae91ae","lessThan":"4f8c63fe0097c9f6ea34409f82f79b3894903d91","status":"affected","versionType":"git"},{"version":"36da806f7fbaee56ad9e81859deec203f9728700","lessThan":"61d5ddbd524c715b224cbe7e9f01da4e05098b19","status":"affected","versionType":"git"},{"version":"6fef032af0092ed5ccb767239a9ac1bc38c08a40","lessThan":"32a7bc6e93be36b37fe61f351d312d358195bd61","status":"affected","versionType":"git"},{"version":"6fef032af0092ed5ccb767239a9ac1bc38c08a40","lessThan":"66d6ef18548ae6d7dd452b84115fc82c0a73a4ea","status":"affected","versionType":"git"},{"version":"733e76e74e406c1d1ddc7369420dd8a47f48bb8a","status":"affected","versionType":"git"},{"version":"6.1.178","lessThan":"6.1.188","status":"affected","versionType":"semver"},{"version":"6.6.145","lessThan":"6.6.157","status":"affected","versionType":"semver"},{"version":"6.12.97","lessThan":"6.12.110","status":"affected","versionType":"semver"},{"version":"6.18.40","lessThan":"6.18.52","status":"affected","versionType":"semver"},{"version":"7.1.5","lessThan":"7.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/l2cap.h","net/bluetooth/l2cap_sock.c"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.178","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.145","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.97","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.40","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/827de6bd2865b22aaabd554540def3b8a33018ab"},{"url":"https://git.kernel.org/stable/c/7c7ac736b50fa259ed1bdddc18d79523f07c0442"},{"url":"https://git.kernel.org/stable/c/4f8c63fe0097c9f6ea34409f82f79b3894903d91"},{"url":"https://git.kernel.org/stable/c/61d5ddbd524c715b224cbe7e9f01da4e05098b19"},{"url":"https://git.kernel.org/stable/c/32a7bc6e93be36b37fe61f351d312d358195bd61"},{"url":"https://git.kernel.org/stable/c/66d6ef18548ae6d7dd452b84115fc82c0a73a4ea"}],"title":"Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan","x_generator":{"engine":"bippy-1.2.0"}}}}