CVE-2026-72336
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
get_l2cap_conn() looks up an LE hci_conn under hdev protection, but then drops that protection before reading hcon->l2cap_data and before lowpan_control_write() later dereferences conn->hcon. A disconnect or device close can tear down the same L2CAP connection in that window.
The buggy scenario involves two paths, with each column showing the order within that path:
Take a reference to the L2CAP connection with l2cap_conn_hold_unless_zero() while hdev is still locked, and drop that reference after the debugfs command's last use of conn.
Leer descripción completaMostrar menos
This mirrors the existing L2CAP ACL receive-side handoff and keeps the connection dereferenceable after leaving hdev protection. Export the existing helper so the bluetooth_6lowpan module can use the same lifetime primitive.
Detalles técnicos trazas, registros y código del informe original
6LoWPAN control write: HCI disconnect/device close:
1. get_l2cap_conn() finds hcon 1. hci_disconn_cfm() dispatches
and hcon->l2cap_data. the L2CAP disconnect callback.
2. get_l2cap_conn() drops hdev 2. l2cap_conn_del() clears
protection and returns conn. hcon->l2cap_data and drops the
L2CAP connection reference.
3. lowpan_control_write() reads 3. hci_conn_del() removes and drops
conn->hcon. the HCI connection.
Validation reproduced this kernel report:
BUG: KASAN: slab-use-after-free in lowpan_control_write+0x374/0x520
The buggy address belongs to the object at ffff888111b9d000 which belongs
to the cache kmalloc-1k of size 1024
The buggy address is located 0 bytes inside of freed 1024-byte region
[ffff888111b9d000, ffff888111b9d400)
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x5f0
lowpan_control_write+0x374/0x520 (net/bluetooth/6lowpan.c:1131)
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x19f/0x330
kasan_report+0xe0/0x110
__debugfs_file_get+0xf7/0x400
full_proxy_write+0x9e/0xd0
vfs_write+0x1b0/0x810
ksys_write+0xd2/0x170
dnotify_flush+0x32/0x220
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x17/0x60
__kasan_kmalloc+0xaa/0xb0
l2cap_conn_add+0x45/0x520
l2cap_chan_connect+0xac6/0xd90
l2cap_sock_connect+0x216/0x350
__sys_connect+0x101/0x130
__x64_sys_connect+0x40/0x50
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x17/0x60
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x5f/0x80
kfree+0x313/0x590
hci_conn_hash_flush+0xc0/0x140
hci_dev_close_sync+0x41a/0xb00
hci_dev_close+0x12f/0x160
hci_sock_ioctl+0x157/0x570
sock_do_ioctl+0xf7/0x210
sock_ioctl+0x32f/0x490
__x64_sys_ioctl+0xc7/0x110
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
kasan_record_aux_stack+0xa7/0xc0
insert_work+0x32/0x100
__queue_work+0x262/0xa60
queue_work_on+0xad/0xb0
l2cap_connect_cfm+0x4ef/0x670
hci_le_remote_feat_complete_evt+0x247/0x430
hci_event_packet+0x360/0x6f0
hci_rx_work+0x2ae/0x7a0
process_one_work+0x4fd/0xbc0
worker_thread+0x2d8/0x570
kthread+0x1ad/0x1f0
ret_from_fork+0x3c9/0x540
ret_from_fork_asm+0x1a/0x30CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/23a83bac3356e7b211bcdcf581a31f7b536a2c24
- https://git.kernel.org/stable/c/32c48c7f6cc8c7888e46a8c81622154ccafda5d2
- https://git.kernel.org/stable/c/518aa9505fa10ea5662349e5d2efd8c9e32a820b
- https://git.kernel.org/stable/c/ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e
- https://git.kernel.org/stable/c/d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72336",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6b8d4a6a03144c5996f98db7f8256267b0d72a3a",
"lessThan": "ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e",
"versionType": "git"
},
{
"status": "affected",
"version": "6b8d4a6a03144c5996f98db7f8256267b0d72a3a",
"lessThan": "d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff",
"versionType": "git"
},
{
"status": "affected",
"version": "6b8d4a6a03144c5996f98db7f8256267b0d72a3a",
"lessThan": "23a83bac3356e7b211bcdcf581a31f7b536a2c24",
"versionType": "git"
},
{
"status": "affected",
"version": "6b8d4a6a03144c5996f98db7f8256267b0d72a3a",
"lessThan": "32c48c7f6cc8c7888e46a8c81622154ccafda5d2",
"versionType": "git"
},
{
"status": "affected",
"version": "6b8d4a6a03144c5996f98db7f8256267b0d72a3a",
"lessThan": "518aa9505fa10ea5662349e5d2efd8c9e32a820b",
"versionType": "git"
}
],
"programFiles": [
"net/bluetooth/6lowpan.c",
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/bluetooth/6lowpan.c",
"net/bluetooth/l2cap_core.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:06.817",
"references": [
{
"url": "https://git.kernel.org/stable/c/23a83bac3356e7b211bcdcf581a31f7b536a2c24",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/32c48c7f6cc8c7888e46a8c81622154ccafda5d2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/518aa9505fa10ea5662349e5d2efd8c9e32a820b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: hold L2CAP conn across debugfs control\n\nget_l2cap_conn() looks up an LE hci_conn under hdev protection, but\nthen drops that protection before reading hcon->l2cap_data and before\nlowpan_control_write() later dereferences conn->hcon. A disconnect or\ndevice close can tear down the same L2CAP connection in that window.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\n6LoWPAN control write: HCI disconnect/device close:\n 1. get_l2cap_conn() finds hcon 1. hci_disconn_cfm() dispatches\n and hcon->l2cap_data. the L2CAP disconnect callback.\n 2. get_l2cap_conn() drops hdev 2. l2cap_conn_del() clears\n protection and returns conn. hcon->l2cap_data and drops the\n L2CAP connection reference.\n 3. lowpan_control_write() reads 3. hci_conn_del() removes and drops\n conn->hcon. the HCI connection.\n\nTake a reference to the L2CAP connection with\nl2cap_conn_hold_unless_zero() while hdev is still locked, and drop that\nreference after the debugfs command's last use of conn. This mirrors the\nexisting L2CAP ACL receive-side handoff and keeps the connection\ndereferenceable after leaving hdev protection. Export the existing helper\nso the bluetooth_6lowpan module can use the same lifetime primitive.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in lowpan_control_write+0x374/0x520\nThe buggy address belongs to the object at ffff888111b9d000 which belongs\nto the cache kmalloc-1k of size 1024\nThe buggy address is located 0 bytes inside of freed 1024-byte region\n[ffff888111b9d000, ffff888111b9d400)\nRead of size 8\nCall trace:\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x5f0\n lowpan_control_write+0x374/0x520 (net/bluetooth/6lowpan.c:1131)\n srso_alias_return_thunk+0x5/0xfbef5\n __virt_addr_valid+0x19f/0x330\n kasan_report+0xe0/0x110\n __debugfs_file_get+0xf7/0x400\n full_proxy_write+0x9e/0xd0\n vfs_write+0x1b0/0x810\n ksys_write+0xd2/0x170\n dnotify_flush+0x32/0x220\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nAllocated by task stack:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x17/0x60\n __kasan_kmalloc+0xaa/0xb0\n l2cap_conn_add+0x45/0x520\n l2cap_chan_connect+0xac6/0xd90\n l2cap_sock_connect+0x216/0x350\n __sys_connect+0x101/0x130\n __x64_sys_connect+0x40/0x50\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nFreed by task stack:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x17/0x60\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x5f/0x80\n kfree+0x313/0x590\n hci_conn_hash_flush+0xc0/0x140\n hci_dev_close_sync+0x41a/0xb00\n hci_dev_close+0x12f/0x160\n hci_sock_ioctl+0x157/0x570\n sock_do_ioctl+0xf7/0x210\n sock_ioctl+0x32f/0x490\n __x64_sys_ioctl+0xc7/0x110\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n kasan_record_aux_stack+0xa7/0xc0\n insert_work+0x32/0x100\n __queue_work+0x262/0xa60\n queue_work_on+0xad/0xb0\n l2cap_connect_cfm+0x4ef/0x670\n hci_le_remote_feat_complete_evt+0x247/0x430\n hci_event_packet+0x360/0x6f0\n hci_rx_work+0x2ae/0x7a0\n process_one_work+0x4fd/0xbc0\n worker_thread+0x2d8/0x570\n kthread+0x1ad/0x1f0\n ret_from_fork+0x3c9/0x540\n ret_from_fork_asm+0x1a/0x30"
}
],
"lastModified": "2026-08-17T06:18:37.290",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}