{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90255","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.796Z","datePublished":"2026-09-17T16:07:54.775Z","dateUpdated":"2026-09-18T17:54:11.196Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:11.196Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: fix the SCO setup context lifetime\n\nhci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so\nthe context is only freed if hci_enhanced_setup_sync() actually runs. An\nentry that is cancelled instead is leaked, as\n_hci_cmd_sync_cancel_entry() does not release entry->data when there is\nno destroy callback, and hci_cmd_sync_clear() cancels every pending entry\nwhen the controller is unregistered.\n\nThe context also stores a bare hci_conn pointer, so the connection can be\nfreed while the work is queued. The dequeue in hci_conn_del() does not\ncover it either, as it matches on entry->data == conn and entry->data is\nthe wrapper here. Same problem as commit 2f5d635ad590 (\"Bluetooth:\nhci_sync: hold conn in hci_connect_acl/le_sync() callbacks\").\n\nHold the connection and release both from a destroy callback. The\nsubmission failure path drops both, since hci_cmd_sync_submit() does not\ncall the destroy callback when it fails to queue."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - hci_setup_sync() is reached from hci_sco_setup() on ACL HCI Connection Complete (hci_conn_complete_evt) and from hci_sync_conn_complete_evt retrying Enhanced Setup Synchronous Connection on remote error statuses (0x1a, 0x1c, 0x1e, 0x1f); those HCI events arrive over Bluetooth radio, scored Adjacent.\nAC:L - An attacker queues hci_enhanced_setup_sync via hci_setup_sync() (sco_connect->hci_connect_sco->hci_sco_setup, or Sync Conn Complete retries) then frees that SCO hci_conn with hci_conn_del (socket close, hci_disconn_complete_evt, or hci_setup_sync_conn_status). Dequeue matches entry->data==conn but data is the conn_handle_t wrapper, so both sides of the race are attacker-controlled.\nPR:N - A radio-adjacent peer needs no Linux account: HFP/PipeWire stacks cause the host to call hci_setup_sync, and the peer's Disconnection Complete or Synchronous Connection Complete events run hci_conn_del. Locally sco_sock_create() has no capability check (AF_BLUETOOTH is init_net only).\nUI:N - No extra victim action at exploit time: Bluetooth audio stacks automatically open outgoing SCO for a connected HFP/headset, and a local attacker uses their own BTPROTO_SCO sockets rather than inducing another user to mount or open a file.\nS:U - The use-after-free corrupts kernel heap (struct hci_conn) in the host Bluetooth stack and can escalate privileges in that same kernel authority; it does not cross a VM, guest-to-host, or IOMMU boundary.\nC:H - hci_enhanced_setup_sync() reads conn_handle->conn, kfree()s the wrapper, then uses conn (conn->codec, conn->parent, conn->attempt) after only a pointer-compare hci_conn_valid() check, so a freed or slab-reused hci_conn yields arbitrary kernel reads.\nI:H - The same callback writes conn->state, conn->out, and conn->attempt and builds HCI_OP_ENHANCED_SETUP_SYNC_CONN from freed codec fields; struct hci_conn has cleanup/connect_cfm_cb pointers, so slab reuse gives a kernel write and control-flow primitive.\nA:H - Dereferencing a freed hci_conn from hci_cmd_sync_work on req_workqueue causes a kernel oops or panic; UAF availability is High even without full exploitation. Cancelled cmd_sync entries also leak conn_handle_t because destroy was NULL."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hci_conn.c"],"versions":[{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"37cfec41365c826d5496ef5d00c9e215eee53aa2","status":"affected","versionType":"git"},{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"9a2ba69cebe3fc5a3d4fa8eaaad3c42862723c27","status":"affected","versionType":"git"},{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"a661de0ee29d0915c5e924edf91d2be2b4d35bae","status":"affected","versionType":"git"},{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"c1fe3c74a89a7749cba3caa0dd91236049c66116","status":"affected","versionType":"git"},{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"4d7b1c834d2775b73c65e4888e01f5af8b477fe9","status":"affected","versionType":"git"},{"version":"e07a06b4eb417f5271d33ce2240e93c62d98b7b4","lessThan":"42de40abe25db9211107af8896d0fd741f10648d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hci_conn.c"],"versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/37cfec41365c826d5496ef5d00c9e215eee53aa2"},{"url":"https://git.kernel.org/stable/c/9a2ba69cebe3fc5a3d4fa8eaaad3c42862723c27"},{"url":"https://git.kernel.org/stable/c/a661de0ee29d0915c5e924edf91d2be2b4d35bae"},{"url":"https://git.kernel.org/stable/c/c1fe3c74a89a7749cba3caa0dd91236049c66116"},{"url":"https://git.kernel.org/stable/c/4d7b1c834d2775b73c65e4888e01f5af8b477fe9"},{"url":"https://git.kernel.org/stable/c/42de40abe25db9211107af8896d0fd741f10648d"}],"title":"Bluetooth: hci_conn: fix the SCO setup context lifetime","x_generator":{"engine":"bippy-1.2.0"}}}}