CVE-2026-68188
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: Fix session UAF in set_termios
rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initiator and session->sock. Meanwhile, krfcommd can unlink the DLC and free the session while holding rfcomm_mutex.
The race can proceed as follows:
Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies that the DLC is still attached and sends the RPN frame. Have the TTY path use the helper and drop its unlocked session check. This keeps the session valid through both the frame construction and socket send.
Detalles técnicos trazas, registros y código del informe original
TTY ioctl task krfcommd
-------------- --------
load dlc->session
enter rfcomm_send_rpn()
lock rfcomm_mutex
clear dlc->session
free session
unlock rfcomm_mutex
read session->initiator
KASAN reported:
BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0
Read of size 4 at addr ffff88810012a850 by task poc/92
Call Trace:
rfcomm_send_rpn+0x297/0x2a0
rfcomm_tty_set_termios+0x50d/0x850
tty_set_termios+0x596/0x950
set_termios+0x46a/0x6e0
tty_mode_ioctl+0x152/0xbd0
tty_ioctl+0x915/0x1240
__x64_sys_ioctl+0x134/0x1c0
Allocated by task 92:
rfcomm_session_add+0x9e/0x2e0
rfcomm_dlc_open+0x8b1/0xe00
rfcomm_dev_activate+0x85/0x1a0
rfcomm_tty_open+0x90/0x280
Freed by task 68:
kfree+0x131/0x3c0
rfcomm_session_del+0x119/0x180
rfcomm_run+0x737/0x4710CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c
- https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea
- https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6
- https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078
- https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea
- https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b
- https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0
- https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68188",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "4eac4576a072084b06459de6c054b4ebc764b4ea",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "82c383f9031f1ce919ac6c3c06bc5bd492a6b078",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "c5c060597247131f90f39ea7c8c978fa0c2e79d0",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "2894bd8c68e97accd758ca6e5fc375d7e9e8882c",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "a82a9d3891f5607030b0672c255087a12bb9837b",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "780b04d09c941262ee2a2b4a09906451b69df8a6",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea",
"versionType": "git"
},
{
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"lessThan": "c783399efc22d035443f1dfbf2a09bf9562aaa5e",
"versionType": "git"
}
],
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:06.020",
"references": [
{
"url": "https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: Fix session UAF in set_termios\n\nrfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and\nlater passes the pointer to rfcomm_send_rpn(). The latter dereferences\nboth session->initiator and session->sock. Meanwhile, krfcommd can\nunlink the DLC and free the session while holding rfcomm_mutex.\n\nThe race can proceed as follows:\n\n TTY ioctl task krfcommd\n -------------- --------\n load dlc->session\n enter rfcomm_send_rpn()\n lock rfcomm_mutex\n clear dlc->session\n free session\n unlock rfcomm_mutex\n read session->initiator\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0\n Read of size 4 at addr ffff88810012a850 by task poc/92\n\n Call Trace:\n rfcomm_send_rpn+0x297/0x2a0\n rfcomm_tty_set_termios+0x50d/0x850\n tty_set_termios+0x596/0x950\n set_termios+0x46a/0x6e0\n tty_mode_ioctl+0x152/0xbd0\n tty_ioctl+0x915/0x1240\n __x64_sys_ioctl+0x134/0x1c0\n\n Allocated by task 92:\n rfcomm_session_add+0x9e/0x2e0\n rfcomm_dlc_open+0x8b1/0xe00\n rfcomm_dev_activate+0x85/0x1a0\n rfcomm_tty_open+0x90/0x280\n\n Freed by task 68:\n kfree+0x131/0x3c0\n rfcomm_session_del+0x119/0x180\n rfcomm_run+0x737/0x4710\n\nAdd rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies\nthat the DLC is still attached and sends the RPN frame. Have the TTY\npath use the helper and drop its unlocked session check. This keeps the\nsession valid through both the frame construction and socket send."
}
],
"lastModified": "2026-08-19T17:20:35.003",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}