« Volver al listado

CVE-2026-98290

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup

rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock.

Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt_accept_dequeue() locks the child while unlinking it and clearing its parent pointer.

Leer descripción completaMostrar menos

Dropping the child lock makes it important to prevent a concurrent rfcomm_connect_ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT_CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm_connect_ind() then rejects new children once cleanup starts.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98290",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "4aafb47301a799d3e01230d6568c4e93524e1523",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "c741977e413f5b49d306700820fb55ccb8269f5a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "c6792c441767256030606eb82dca5d5fc360dd9a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "bfce253f039eb5f58b810af267942a9f59207254",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "18174b166547ef41973cc19feb5ef9cab39a8def",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b7ce436a5d798bc59e71797952566608a4b4626b",
              "lessThan": "801fb950cae7048eb7d83b18857d1ca37b8cd5a4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bluetooth/rfcomm/sock.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/rfcomm/sock.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:19.317",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which takes the child socket lock before\nrfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these\nlocks in reverse order while handling connections and DLC state changes,\nso lockdep reports a possible deadlock.\n\nClose dequeued children without taking their socket lock. The accept queue\nowns a reference to each child, and bt_accept_dequeue() locks the child\nwhile unlinking it and clearing its parent pointer.\n\nDropping the child lock makes it important to prevent a concurrent\nrfcomm_connect_ind() from enqueueing a new child after cleanup observes an\nempty queue. Set a listening socket to BT_CLOSED while its lock is still\nheld, before dropping the lock and draining the queue. The state check in\nrfcomm_connect_ind() then rejects new children once cleanup starts."
    }
  ],
  "lastModified": "2026-10-06T09:18:19.317",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}