{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90256","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.796Z","datePublished":"2026-09-17T16:07:55.427Z","dateUpdated":"2026-09-18T17:54:12.512Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:12.512Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind\n\nhci_conn::l2cap_data is accessed without locks in l2cap_disconn_ind via\nhci_conn_timeout (disc_work) -> hci_proto_disconn_ind ->\nl2cap_disconn_ind.  This is UAF if the l2cap_conn is deleted\nconcurrently.\n\ndisc_work is disabled sync in hci_conn_del(), so we cannot take\nhci_dev_lock in disc_work.\n\nFix by using proto_lock to guard l2cap_data, in addition to hdev->lock\nwhich is held in other access paths."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - l2cap_disconn_ind() is reached from hci_conn_timeout() (hci_conn.disc_work) via hci_proto_disconn_ind() only for ACL_LINK/LE_LINK; hcon->l2cap_data is installed by l2cap_conn_add() from l2cap_connect_cfm()/l2cap_chan_connect() on that HCI connection, so the triggering peer must be in Bluetooth radio range.\nAC:L - The attacker creates the ACL/LE link so l2cap_conn_add() publishes hcon->l2cap_data, then tears it down so l2cap_conn_del() or the last l2cap_conn_put() from l2cap_chan_destroy() (rfcomm_process_rx on rfcomm_run) frees the object while hci_conn_timeout() reads conn->disc_reason; both sides are attacker-driven and retryable.\nPR:N - HCI Connection Complete delivers l2cap_connect_cfm() → l2cap_conn_add() and later disc_work with no host uid or capability check; SDP (PSM 0x0001) and RFCOMM session close on remote disconnect likewise need no pairing, so an unauthenticated Bluetooth peer is enough.\nUI:N - hci_conn_timeout() runs from hdev->workqueue after the last hci_conn_drop() once the adapter is powered and connectable; incoming ACL/LE setup, RFCOMM/L2CAP teardown, and the disconnect timer need no per-attack user click.\nS:U - The UAF is of the host kmalloc l2cap_conn used by l2cap_disconn_ind() and only corrupts that kernel's Bluetooth/HCI state, with no VM, IOMMU, or sandbox boundary crossing.\nC:H - l2cap_disconn_ind() locklessly loads hcon->l2cap_data and reads conn->disc_reason after l2cap_conn_free() has kfree'd the kmalloc-1k object, so a sprayed replacement discloses kernel heap contents through that dangling pointer.\nI:H - The same freed l2cap_conn can be reallocated under attacker control while hci_conn_timeout() still holds the pointer; heap UAF of this object enables spraying and write/control-flow hijack, and the stale disc_reason is consumed as the HCI abort reason.\nA:H - The syzbot report is a slab-use-after-free read of conn->disc_reason in l2cap_disconn_ind() from the hci_conn_timeout worker, which oopses or panics the kernel when the freed l2cap_conn slab is touched."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_core.c"],"versions":[{"version":"ab4eedb790cae44313759b50fe47da285e2519d5","lessThan":"b495a3a9b33bc4e4613e685bf5c96c136caa22d8","status":"affected","versionType":"git"},{"version":"ab4eedb790cae44313759b50fe47da285e2519d5","lessThan":"2b66c83ff1751d6bd3201b3017206262ab46dc05","status":"affected","versionType":"git"},{"version":"efc30877bd4bc85fefe98d80af60fafc86e5775e","status":"affected","versionType":"git"},{"version":"f87271d21dd4ee83857ca11b94e7b4952749bbae","status":"affected","versionType":"git"},{"version":"18ab6b6078fa8191ca30a3065d57bf35d5635761","status":"affected","versionType":"git"},{"version":"6.6.84","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.12.20","lessThan":"6.13","status":"affected","versionType":"semver"},{"version":"6.13.8","lessThan":"6.14","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/l2cap_core.c"],"versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.84"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.20"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b495a3a9b33bc4e4613e685bf5c96c136caa22d8"},{"url":"https://git.kernel.org/stable/c/2b66c83ff1751d6bd3201b3017206262ab46dc05"}],"title":"Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind","x_generator":{"engine":"bippy-1.2.0"}}}}