« Volver al listado

CVE-2026-98246

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: Serialize local codec list cleanup

hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock. Codec list additions and both traversals in sco_sock_getsockopt() use that lock, but the close path does not. A close and BT_CODEC query can therefore interleave as follows:

The reader then accesses an entry which the close path has freed. KASAN

Take hdev->lock around the clear operation at its existing point in the close path. This makes the clear wait for active readers and prevents a new traversal until the list is empty without changing teardown ordering.

Detalles técnicos trazas, registros y código del informe original
  hci_dev_close_sync()          sco_sock_getsockopt()
                                hci_dev_lock()
                                fetch codec entry
  hci_codec_list_clear()
    kfree(entry)
                                read entry->id

  BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0
  Read of size 1 at addr ffff8881001c3450
  Call Trace:
   sco_sock_getsockopt+0xfa0/0xfe0
   do_sock_getsockopt+0x537/0x7b0
   __sys_getsockopt+0xf2/0x170
  Allocated by task 92:
   hci_codec_list_add.isra.0+0x2c/0x440
   hci_read_codec_capabilities+0x224/0x590
   hci_read_supported_codecs+0x2c2/0x640
  Freed by task 92:
   kfree+0x131/0x3c0
   hci_codec_list_clear+0xd8/0x160
   hci_dev_close_sync+0x92a/0xfa0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98246",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "626535077ba9dc110787540d1fe24881094c15a1",
              "lessThan": "9f407d52c0d881430d689836d3e7d32aa36f98b5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b938790e70540bf4f2e653dcd74b232494d06c8f",
              "lessThan": "560ed4373c06a58123ecdf9ad5ecaddc87a73382",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b938790e70540bf4f2e653dcd74b232494d06c8f",
              "lessThan": "1ee0c5429dc4a92879bda2554b1bfd4abc6c587c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b938790e70540bf4f2e653dcd74b232494d06c8f",
              "lessThan": "4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b938790e70540bf4f2e653dcd74b232494d06c8f",
              "lessThan": "1276c2fafd18499769a28f96f45c5a76d6fc990e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b938790e70540bf4f2e653dcd74b232494d06c8f",
              "lessThan": "9a10987a2f160a44a638c9a35994ca6e3089696e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eea5a8f0c3b7c884d2351e75fbdd0a3d7def5ae1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.57",
              "lessThan": "6.1.189",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.5.7",
              "lessThan": "6.6",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_sync.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_sync.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:12.783",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1276c2fafd18499769a28f96f45c5a76d6fc990e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1ee0c5429dc4a92879bda2554b1bfd4abc6c587c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/560ed4373c06a58123ecdf9ad5ecaddc87a73382",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a10987a2f160a44a638c9a35994ca6e3089696e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9f407d52c0d881430d689836d3e7d32aa36f98b5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Serialize local codec list cleanup\n\nhci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock.\nCodec list additions and both traversals in sco_sock_getsockopt() use that\nlock, but the close path does not. A close and BT_CODEC query can therefore\ninterleave as follows:\n\n  hci_dev_close_sync()          sco_sock_getsockopt()\n                                hci_dev_lock()\n                                fetch codec entry\n  hci_codec_list_clear()\n    kfree(entry)\n                                read entry->id\n\nThe reader then accesses an entry which the close path has freed. KASAN\n\n  BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0\n  Read of size 1 at addr ffff8881001c3450\n  Call Trace:\n   sco_sock_getsockopt+0xfa0/0xfe0\n   do_sock_getsockopt+0x537/0x7b0\n   __sys_getsockopt+0xf2/0x170\n  Allocated by task 92:\n   hci_codec_list_add.isra.0+0x2c/0x440\n   hci_read_codec_capabilities+0x224/0x590\n   hci_read_supported_codecs+0x2c2/0x640\n  Freed by task 92:\n   kfree+0x131/0x3c0\n   hci_codec_list_clear+0xd8/0x160\n   hci_dev_close_sync+0x92a/0xfa0\n\nTake hdev->lock around the clear operation at its existing point in the\nclose path. This makes the clear wait for active readers and prevents a new\ntraversal until the list is empty without changing teardown ordering."
    }
  ],
  "lastModified": "2026-10-06T09:18:12.783",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}