5.5

CVE-2026-31499

Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()

l2cap_conn_del() calls cancel_delayed_work_sync() for both info_timer
and id_addr_timer while holding conn->lock. However, the work functions
l2cap_info_timeout() and l2cap_conn_update_id_addr() both acquire
conn->lock, creating a potential AB-BA deadlock if the work is already
executing when l2cap_conn_del() takes the lock.

Move the work cancellations before acquiring conn->lock and use
disable_delayed_work_sync() to additionally prevent the works from
being rearmed after cancellation, consistent with the pattern used in
hci_conn_del().
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.6.84 < 6.7
Linux ≫ Linux Kernel Version >= 6.12.20 < 6.13
Linux ≫ Linux Kernel Version >= 6.13.8 < 6.14
Linux ≫ Linux Kernel Version >= 6.14.1 < 6.18.21
Linux ≫ Linux Kernel Version >= 6.19 < 6.19.11
Linux ≫ Linux Kernel Version 6.14 Update -
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
Linux ≫ Linux Kernel Version 7.0 Update rc3
Linux ≫ Linux Kernel Version 7.0 Update rc4
Linux ≫ Linux Kernel Version 7.0 Update rc5
Linux ≫ Linux Kernel Version 7.0 Update rc6
Linux ≫ Linux Kernel Version 7.0 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.008
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

https://git.kernel.org/stable/c/00fdebbbc557a2fc21321ff2eaa22fd70c078608
Patch
https://git.kernel.org/stable/c/3f26ecbd9cde621dd94be7ef252c7210b965a5c7
Patch
https://git.kernel.org/stable/c/d008460de352e534f6721de829b093368564ec66
Patch
https://git.kernel.org/stable/c/f7f35a4f7fd574f5889bb2e4b397e14cbb83f6da