CVE-2026-90091
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90091, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-18

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan For L2CAP sockets without owning sk->sk_socket, reading l2cap_pi(sk)->chan may race against concurrent l2cap_sock_kill() -> l2cap_sock_put_chan(). This excludes simultaneous proto_ops callbacks, but access in l2cap_sock_cleanup_listen() has unsafe lockless read. [Task 1] [Task 2 (hdev->workqueue)] l2cap_sock_release(parent) l2cap_disconn_cfm l2cap_sock_cleanup_listen l2cap_conn_del bt_accept_dequeue l2cap_chan_del lock_sock(sk) l2cap_sock_teardown_cb bt_accept_unlink bt_sk(sk)->parent = NULL release_sock(sk) ----------------> lock_sock(sk) parent = /* NULL */ lock_sock(sk) <--------------------- release_sock(sk) sock_set_flag(sk, SOCK_ZAPPED) l2cap_sock_close_cb l2cap_sock_kill(sk) l2cap_sock_put_chan chan = READ l2cap_pi(sk)->chan l2cap_pi(sk)->chan = NULL l2cap_chan_hold_unless_zero l2cap_put_chan(chan) kref_get_unless_zero(&chan->ref) Task 1 may observe NULL which causes null-ptr-deref. Fix the race by taking lock_sock() in l2cap_sock_kill() to synchronize with l2cap_sock_cleanup_listen(). hold_unless_zero() is not needed here, l2cap_pi(sk)->chan owns reference if it is non-NULL. Clarify code comments vs. locking.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-18
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Linux Linux b39298044e5534612511a2ff5de03ba5f6e7a820
Linux Linux 8c37e4338c801ebb8cee52436c01c41e009f6e87
Linux Linux 84e718b6a814edc84159361f9f454a4e92ae91ae
Linux Linux 36da806f7fbaee56ad9e81859deec203f9728700
Linux Linux 6fef032af0092ed5ccb767239a9ac1bc38c08a40
Linux Linux 6fef032af0092ed5ccb767239a9ac1bc38c08a40
Linux Linux 733e76e74e406c1d1ddc7369420dd8a47f48bb8a
Linux Linux 6.1.178
Linux Linux 6.6.145
Linux Linux 6.12.97
Linux Linux 6.18.40
Linux Linux 7.1.5
Linux Linux 7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart