{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98290","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.336Z","datePublished":"2026-10-06T08:45:50.299Z","dateUpdated":"2026-10-07T06:49:55.796Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:55.796Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which takes the child socket lock before\nrfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these\nlocks in reverse order while handling connections and DLC state changes,\nso lockdep reports a possible deadlock.\n\nClose dequeued children without taking their socket lock. The accept queue\nowns a reference to each child, and bt_accept_dequeue() locks the child\nwhile unlinking it and clearing its parent pointer.\n\nDropping the child lock makes it important to prevent a concurrent\nrfcomm_connect_ind() from enqueueing a new child after cleanup observes an\nempty queue. Set a listening socket to BT_CLOSED while its lock is still\nheld, before dropping the lock and draining the queue. The state check in\nrfcomm_connect_ind() then rejects new children once cleanup starts."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - A Bluetooth peer drives both halves of this bug. Its RFCOMM SABM creates a child in rfcomm_connect_ind(), and its later DISC makes krfcommd call rfcomm_sk_state_change() on that child (taking lock_sock(child) under rfcomm_mutex, and dereferencing bt_sk(child)->parent). Bluetooth requires radio range, so the vector is Adjacent.\nAC:H - The peer can send SABM and DISC at will, but both the ABBA deadlock and the late-enqueue window need the victim to close its listener at that moment. That window runs from rfcomm_sock_shutdown dropping the listener lock to cleanup_listen setting BT_CLOSED, and the peer cannot control when the application closes the socket.\nPR:N - rfcomm_connect_ind() only checks for a BT_LISTEN socket on the channel and for room in the backlog before it enqueues a child, so the peer needs no credentials.\nUI:N - No victim action beyond normal operation is needed. A service closing its RFCOMM listener on its own (exit, restart, or Bluetooth teardown) is a timing condition and is counted in AC:H.\nS:U - The deadlock and the dangling parent pointer both stay inside kernel RFCOMM socket state and do not cross a virtualization or hardware boundary.\nC:H - A child enqueued after the drain keeps bt_sk(sk)->parent pointing at the listener, but bt_accept_enqueue takes no reference on it, so rfcomm_sock_kill frees the listener while the pointer is still live. A later state change then reads the freed sock through parent->sk_data_ready, a use-after-free that can be groomed for disclosure.\nI:H - On the peer's DISC, rfcomm_sk_state_change calls bt_accept_unlink(), which does list_del on the freed listener's accept_q and decrements its backlog, then makes an indirect call through the freed parent->sk_data_ready. That is a write to freed memory and a call through a function pointer an attacker can replace.\nA:H - The ABBA blocks krfcommd forever while it holds rfcomm_mutex (rfcomm_dlc_close in the closer against lock_sock(child) in rfcomm_sk_state_change). That stops all RFCOMM processing and hangs the closing task, and the use-after-free path can oops the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/rfcomm/sock.c"],"versions":[{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"4aafb47301a799d3e01230d6568c4e93524e1523","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"c741977e413f5b49d306700820fb55ccb8269f5a","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"c6792c441767256030606eb82dca5d5fc360dd9a","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"bfce253f039eb5f58b810af267942a9f59207254","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"18174b166547ef41973cc19feb5ef9cab39a8def","status":"affected","versionType":"git"},{"version":"b7ce436a5d798bc59e71797952566608a4b4626b","lessThan":"801fb950cae7048eb7d83b18857d1ca37b8cd5a4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/rfcomm/sock.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c"},{"url":"https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523"},{"url":"https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a"},{"url":"https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a"},{"url":"https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254"},{"url":"https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def"},{"url":"https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4"}],"title":"Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup","x_generator":{"engine":"bippy-1.2.0"}}}}