{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90093","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.786Z","datePublished":"2026-09-17T16:06:06.843Z","dateUpdated":"2026-09-18T17:52:59.418Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:52:59.418Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: access chan->conn safely in get/setsockopt\n\nSince commit b66774b48dd9 (\"Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\")\nl2cap_chan::conn has held reference and remains non-NULL also after the\ncorresponding hci_conn is deleted.  In this state accessing various\nfields eg. hci_conn::hdev is invalid, which leads to KASAN crash in\nl2cap_sock_setsockopt() access of conn->hcon->hdev.\n\nCheck l2cap_chan::conn.hcon corresponds to an alive hci_conn before\ntrying to use it in l2cap_sock.c.  Hold l2cap_chan_lock() in\ngetsockopt/setsockopt to ensure it stays alive, and to avoid data races\nin l2cap_chan fields."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from __sys_setsockopt/__sys_getsockopt_iter into l2cap_sock_setsockopt()/l2cap_sock_getsockopt(), which dereference chan->conn->hcon->hdev after the HCI device is already gone; the trigger is the local BT_FLUSHABLE/BT_SECURITY/BT_PHY sockopt, not a received L2CAP or HCI PDU. Syzbot frees that hdev via vhci_release()->hci_unregister_dev(), which an in-range peer cannot invoke.\nAC:L - After b66774b48dd9, l2cap_chan_del() sets FLAG_DEL but leaves chan->conn non-NULL, so a later setsockopt(SOL_BLUETOOTH, BT_FLUSHABLE, BT_FLUSHABLE_OFF) deterministically hits lmp_no_flush_capable(conn->hcon->hdev) on the deleted hci_conn. The attacker opens the L2CAP socket, tears down the controller (close of /dev/vhci), then issues the sockopt; no un-controllable race or rare config is required.\nPR:L - l2cap_sock_create() requires capable(CAP_NET_RAW) only for SOCK_RAW; SOCK_SEQPACKET/STREAM/DGRAM L2CAP sockets used here have no capability gate, and vhci_open() likewise has no capable() check. An unprivileged init_net user who can open /dev/vhci (or an equivalent HCI node) can create the socket, unregister the controller, and call setsockopt without real root.\nUI:N - The attacker owns both the AF_BLUETOOTH/BTPROTO_L2CAP fd and the teardown fd: they connect, close /dev/vhci so hci_conn_hash_flush()->l2cap_conn_del() runs, then call setsockopt on their still-open socket. No other user must pair, mount, or click anything.\nS:U - l2cap_sock_setsockopt() is using a dangling hci_dev through l2cap_conn->hcon after hci_release_dev(); the resulting slab UAF stays inside the host kernel Bluetooth stack and does not cross a VM, IOMMU, or sandbox authority.\nC:H - KASAN reports a use-after-free/OOB read in l2cap_sock_setsockopt() of conn->hcon->hdev (lmp_no_flush_capable() reads hdev->features[0][6]; getsockopt BT_SECURITY/BT_PHY and L2CAP_CONNINFO also read hcon fields). The freed hci_dev slab was reused as skbuff_small_head, so spraying that object yields a kernel-memory read primitive through the dangling hdev pointer.\nI:H - The same dangling conn->hcon remains usable from setsockopt after FLAG_DEL: BT_SECURITY on an ATT socket calls smp_conn_security(conn->hcon) which touches hcon->hdev flags and hcon->pending_sec_level, and BT_PHY calls hci_conn_set_phy() on that hcon. A sprayed hci_dev in place of the freed object supplies function pointers (send/reset/workqueues) for write and control-flow hijack.\nA:H - Syzbot crashed in l2cap_sock_setsockopt+0x22c3 (net/bluetooth/l2cap_sock.c:1003) with both KASAN slab-out-of-bounds and use-after-free reads of the released hci_dev after vhci_release()->hci_release_dev(). Any such UAF dereference oopses or panics the kernel and can be repeated by open/connect/close/setsockopt."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_sock.c"],"versions":[{"version":"b66774b48dd98f07254951f74ea6f513efe7ff8b","lessThan":"f49321c85785178214fd67f2e9b4b73d6363783b","status":"affected","versionType":"git"},{"version":"b66774b48dd98f07254951f74ea6f513efe7ff8b","lessThan":"ca2c4c26498643f421d35ffe258fafbd3ed461c3","status":"affected","versionType":"git"},{"version":"8f90405a4a6f1f1880dc07996b47bf57c712bd8a","status":"affected","versionType":"git"},{"version":"32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b","status":"affected","versionType":"git"},{"version":"8922c7940bae9ce4b1736dddb6362370793835c2","status":"affected","versionType":"git"},{"version":"91047a4396a8b1857a6f712a90cf33ec0012b189","status":"affected","versionType":"git"},{"version":"0b0e2bf39cf99e458d991b9df253727e036a7d7d","status":"affected","versionType":"git"},{"version":"d3b739db5dc6f688a60d56da872fabaf65246032","status":"affected","versionType":"git"},{"version":"50c38d9f42a529691e4e67ea9cedf4f0bfc8d277","status":"affected","versionType":"git"},{"version":"5.10.265","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.15.216","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"6.1.183","lessThan":"6.2","status":"affected","versionType":"semver"},{"version":"6.6.145","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.12.97","lessThan":"6.13","status":"affected","versionType":"semver"},{"version":"6.18.39","lessThan":"6.19","status":"affected","versionType":"semver"},{"version":"7.1.4","lessThan":"7.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_sock.c"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f49321c85785178214fd67f2e9b4b73d6363783b"},{"url":"https://git.kernel.org/stable/c/ca2c4c26498643f421d35ffe258fafbd3ed461c3"}],"title":"Bluetooth: L2CAP: access chan->conn safely in get/setsockopt","x_generator":{"engine":"bippy-1.2.0"}}}}