-

CVE-2026-98297

Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained

hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work
unconditionally. They can run from the L2CAP/SCO/ISO socket send path
while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN
racing with a socket write). Since that queue_work() is not chained
work from the tx_work worker itself, __queue_work() sees the queue
marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops
the work:

  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
  Call Trace:
   queue_work_on
   l2cap_chan_send
   l2cap_sock_sendmsg
   ...

hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before
draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()
check it before queuing. Route the tx_work producers through the
same guard via a shared hci_sched_tx() helper.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9
Version < ab0678a0701ac4de499428dc1b321659bb74d272
Status affected
Version 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e
Version < e220c1242a643d97102a79f09b7ef3aa31276961
Status affected
Version 525daaea459fc215f432de1b8debbd9144bf97b0
Version < cbb325bc150e8c0dbce004ac0e5516bcffc0de31
Status affected
Version 525daaea459fc215f432de1b8debbd9144bf97b0
Version < 6610c6fe4b8936c232048e6049bf77c70a6f759c
Status affected
Version 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff
Status affected
Version 6.12.93
Version < 6.12.112
Status affected
Version 6.18.35
Version < 6.18.54
Status affected
Version 7.0.12
Version < 7.1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ab0678a0701ac4de499428dc1b321659bb74d272
https://git.kernel.org/stable/c/e220c1242a643d97102a79f09b7ef3aa31276961
https://git.kernel.org/stable/c/cbb325bc150e8c0dbce004ac0e5516bcffc0de31
https://git.kernel.org/stable/c/6610c6fe4b8936c232048e6049bf77c70a6f759c