7.5

CVE-2026-98290

Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup

rfcomm_sock_cleanup_listen() closes unaccepted child sockets through
rfcomm_sock_close(), which takes the child socket lock before
rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.

Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt_accept_dequeue() locks the child
while unlinking it and clearing its parent pointer.

Dropping the child lock makes it important to prevent a concurrent
rfcomm_connect_ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT_CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm_connect_ind() then rejects new children once cleanup starts.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < 4aafb47301a799d3e01230d6568c4e93524e1523
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < c741977e413f5b49d306700820fb55ccb8269f5a
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < c6792c441767256030606eb82dca5d5fc360dd9a
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < bfce253f039eb5f58b810af267942a9f59207254
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < 18174b166547ef41973cc19feb5ef9cab39a8def
Status affected
Version b7ce436a5d798bc59e71797952566608a4b4626b
Version < 801fb950cae7048eb7d83b18857d1ca37b8cd5a4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.159
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c
https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523
https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a
https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a
https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254
https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def
https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4