-

CVE-2026-98246

Bluetooth: hci_sync: Serialize local codec list cleanup

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: Serialize local codec list cleanup

hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock.
Codec list additions and both traversals in sco_sock_getsockopt() use that
lock, but the close path does not. A close and BT_CODEC query can therefore
interleave as follows:

  hci_dev_close_sync()          sco_sock_getsockopt()
                                hci_dev_lock()
                                fetch codec entry
  hci_codec_list_clear()
    kfree(entry)
                                read entry->id

The reader then accesses an entry which the close path has freed. KASAN

  BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0
  Read of size 1 at addr ffff8881001c3450
  Call Trace:
   sco_sock_getsockopt+0xfa0/0xfe0
   do_sock_getsockopt+0x537/0x7b0
   __sys_getsockopt+0xf2/0x170
  Allocated by task 92:
   hci_codec_list_add.isra.0+0x2c/0x440
   hci_read_codec_capabilities+0x224/0x590
   hci_read_supported_codecs+0x2c2/0x640
  Freed by task 92:
   kfree+0x131/0x3c0
   hci_codec_list_clear+0xd8/0x160
   hci_dev_close_sync+0x92a/0xfa0

Take hdev->lock around the clear operation at its existing point in the
close path. This makes the clear wait for active readers and prevents a new
traversal until the list is empty without changing teardown ordering.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 626535077ba9dc110787540d1fe24881094c15a1
Version < 9f407d52c0d881430d689836d3e7d32aa36f98b5
Status affected
Version b938790e70540bf4f2e653dcd74b232494d06c8f
Version < 560ed4373c06a58123ecdf9ad5ecaddc87a73382
Status affected
Version b938790e70540bf4f2e653dcd74b232494d06c8f
Version < 1ee0c5429dc4a92879bda2554b1bfd4abc6c587c
Status affected
Version b938790e70540bf4f2e653dcd74b232494d06c8f
Version < 4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00
Status affected
Version b938790e70540bf4f2e653dcd74b232494d06c8f
Version < 1276c2fafd18499769a28f96f45c5a76d6fc990e
Status affected
Version b938790e70540bf4f2e653dcd74b232494d06c8f
Version < 9a10987a2f160a44a638c9a35994ca6e3089696e
Status affected
Version eea5a8f0c3b7c884d2351e75fbdd0a3d7def5ae1
Status affected
Version 6.1.57
Version < 6.1.189
Status affected
Version 6.5.7
Version < 6.6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9f407d52c0d881430d689836d3e7d32aa36f98b5
https://git.kernel.org/stable/c/560ed4373c06a58123ecdf9ad5ecaddc87a73382
https://git.kernel.org/stable/c/1ee0c5429dc4a92879bda2554b1bfd4abc6c587c
https://git.kernel.org/stable/c/4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00
https://git.kernel.org/stable/c/1276c2fafd18499769a28f96f45c5a76d6fc990e
https://git.kernel.org/stable/c/9a10987a2f160a44a638c9a35994ca6e3089696e