« Volver al listado

CVE-2026-98297

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained

hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work unconditionally. They can run from the L2CAP/SCO/ISO socket send path while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN racing with a socket write). Since that queue_work() is not chained work from the tx_work worker itself, __queue_work() sees the queue marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops the work:

hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer() check it before queuing. Route the tx_work producers through the same guard via a shared hci_sched_tx() helper.

Detalles técnicos trazas, registros y código del informe original
  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
  Call Trace:
   queue_work_on
   l2cap_chan_send
   l2cap_sock_sendmsg
   ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98297",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9cebe4680bb9a72f80c6541eb24af06db7a1fbc9",
              "lessThan": "ab0678a0701ac4de499428dc1b321659bb74d272",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "47330cc875b36a1cf7b3543cb2cf90a7c603ce0e",
              "lessThan": "e220c1242a643d97102a79f09b7ef3aa31276961",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
              "lessThan": "cbb325bc150e8c0dbce004ac0e5516bcffc0de31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
              "lessThan": "6610c6fe4b8936c232048e6049bf77c70a6f759c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.93",
              "lessThan": "6.12.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.35",
              "lessThan": "6.18.54",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.12",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:20.400",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6610c6fe4b8936c232048e6049bf77c70a6f759c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab0678a0701ac4de499428dc1b321659bb74d272",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cbb325bc150e8c0dbce004ac0e5516bcffc0de31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e220c1242a643d97102a79f09b7ef3aa31276961",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix queuing tx_work after workqueue is drained\n\nhci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work\nunconditionally. They can run from the L2CAP/SCO/ISO socket send path\nwhile hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN\nracing with a socket write). Since that queue_work() is not chained\nwork from the tx_work worker itself, __queue_work() sees the queue\nmarked __WQ_DRAINING, warns \"cannot queue %ps on wq %s\", and drops\nthe work:\n\n  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work\n  Call Trace:\n   queue_work_on\n   l2cap_chan_send\n   l2cap_sock_sendmsg\n   ...\n\nhci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before\ndraining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()\ncheck it before queuing. Route the tx_work producers through the\nsame guard via a shared hci_sched_tx() helper."
    }
  ],
  "lastModified": "2026-10-06T09:18:20.400",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}