{"id":"CVE-2026-90092","published":"2026-09-17T17:17:00.757","lastModified":"2026-09-18T18:17:41.517","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: reject accept queue add unless BT_LISTEN\n\nNew sk should not be added to parent socket accept queue after last\nl2cap_sock_cleanup_listen() has run in l2cap_sock_teardown_cb() and\nstate set to BT_CLOSED, as that can result to UAF on dereferencing the\ndangling parent reference.\n\nl2cap_sock_new_connection_cb() may race with parent l2cap_chan teardown,\ndue to chan->state accessed without consistent locking:\n\n  [Task 1]                           [Task 2]\n  l2cap_sock_release(parent)         l2cap_connect\n    l2cap_sock_shutdown                pchan = l2cap_global_chan_by_psm\n      l2cap_chan_lock(pchan)\n      l2cap_chan_close\n        l2cap_sock_teardown_cb\n          pchan->state = BT_CLOSED\n      l2cap_chan_unlock(pchan) ------> l2cap_chan_lock(pchan)\n                                       l2cap_new_connection\n                                         l2cap_sock_new_connection_cb\n      l2cap_chan_lock(pchan) <-------- l2cap_chan_unlock(pchan)\n      l2cap_sock_kill(parent)          /* bt_sk(sk)->parent dangling */\n\nFix by adding check for sk_state == BT_LISTEN after acquiring sk lock in\nl2cap_sock_new_connection_cb().  Add lock_sock() around sk_state writes\nwhere missing, to avoid data races.\n\nAlthough the data races on pchan->state should be fixed too, this\ndefensive sk_state check probably makes sense in any case.","cvssScore":8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2a3a27aaf19bf069720e024ce6fde54e6bf80df9","tags":[]},{"url":"https://git.kernel.org/stable/c/491e4c60017969b053888029998d2a61f298986a","tags":[]},{"url":"https://git.kernel.org/stable/c/87276dc15b559d32757a43b4415c8445fbae06c4","tags":[]},{"url":"https://git.kernel.org/stable/c/bf61a65c6093970e3b50031c4b79ebf3bd411eba","tags":[]},{"url":"https://git.kernel.org/stable/c/c47339e169bf4a0a4cfabb91351471f67744c2bc","tags":[]},{"url":"https://git.kernel.org/stable/c/d4bfa78fd67929b62b02013c107973e0c5b7aa9a","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}