-

CVE-2026-80819

Medienbericht

Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept

rfcomm_sock_recvmsg() completes a deferred setup by calling
rfcomm_dlc_accept() without holding any RFCOMM lock:

	if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {
		rfcomm_dlc_accept(d);
		return 0;
	}

and rfcomm_dlc_accept() dereferences the session on its first line:

	struct sock *sk = d->session->sock->sk;

Every other path that touches d->session runs under rfcomm_mutex:
rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),
rfcomm_dlc_send_rpn(), and the RFCOMM thread through
rfcomm_process_sessions(). rfcomm_connect_ind() is even documented as
"called under rfcomm_lock()". This call site is the only one that skips
it.

The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against
teardown, since __rfcomm_dlc_close() returns early when it wins the
test_and_clear. But rfcomm_recv_disc() forces the state first:

	d->state = BT_CLOSED;
	__rfcomm_dlc_close(d, err);

and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and
BT_CONNECT2. With the state already BT_CLOSED that switch does not
match, the bit is never consulted, and __rfcomm_dlc_close() falls
through to rfcomm_dlc_unlink(), which sets d->session = NULL.

So a remote DISC on a deferred dlc clears the session while leaving
RFCOMM_DEFER_SETUP set. The next recvmsg() then passes the
test_and_clear and dereferences a NULL session. No timing window is
needed: once the DISC has been processed, the dereference is
unconditional.

Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and
rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and
re-checks the session, around a __rfcomm_dlc_accept() that the two
in-core callers, which already hold the mutex, keep using.

Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated
over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the
RFCOMM PSM, starts a session, opens a dlc on a channel bound with
BT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on
the accepted socket then hits:

  Oops: general protection fault
  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
  RIP: 0010:rfcomm_dlc_accept+0x54/0x350
  Call Trace:
    rfcomm_sock_recvmsg+0x1cd/0x230
    sock_recvmsg+0x166/0x1c0
    __sys_recvfrom+0x20d/0x300

0x10 is the offset of sock in struct rfcomm_session. With this patch the
same run completes with recv() returning 0 and no report, and lockdep
stays quiet, confirming rfcomm_mutex is still taken before lock_sock on
this path as it is on the thread side.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < d8d686dd5662a7c4745e4515f1237a9f3b7df181
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < 56f0aa75c7640e46397ef73bea251fcbef9150c0
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < 362726c9c6e56eea4262109183e49868c39ccd3a
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < 825b95561d7b7c393df9e7bc295451aaeadc3d18
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < d4b1a13b1eff2e80925c7368ffdeaaa50cba93df
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < 355bfd57ca4ca881c6eb03ca813b440a094b1f44
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < b405c2f96ae2e37375105881890f7738833b1d62
Status affected
Version bb23c0ab824653be4aa7dfca15b07b3059717004
Version < 43a556b2fd43f2df6dded59c2e26560a27874c24
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.30
Status affected
Version 0
Version < 2.6.30
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/d8d686dd5662a7c4745e4515f1237a9f3b7df181
https://git.kernel.org/stable/c/eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2
https://git.kernel.org/stable/c/56f0aa75c7640e46397ef73bea251fcbef9150c0
https://git.kernel.org/stable/c/362726c9c6e56eea4262109183e49868c39ccd3a
https://git.kernel.org/stable/c/825b95561d7b7c393df9e7bc295451aaeadc3d18
https://git.kernel.org/stable/c/d4b1a13b1eff2e80925c7368ffdeaaa50cba93df
https://git.kernel.org/stable/c/355bfd57ca4ca881c6eb03ca813b440a094b1f44
https://git.kernel.org/stable/c/b405c2f96ae2e37375105881890f7738833b1d62
https://git.kernel.org/stable/c/43a556b2fd43f2df6dded59c2e26560a27874c24