CVE-2026-90091
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90091, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan
For L2CAP sockets without owning sk->sk_socket, reading
l2cap_pi(sk)->chan may race against concurrent l2cap_sock_kill() ->
l2cap_sock_put_chan(). This excludes simultaneous proto_ops callbacks,
but access in l2cap_sock_cleanup_listen() has unsafe lockless read.
[Task 1] [Task 2 (hdev->workqueue)]
l2cap_sock_release(parent) l2cap_disconn_cfm
l2cap_sock_cleanup_listen l2cap_conn_del
bt_accept_dequeue l2cap_chan_del
lock_sock(sk) l2cap_sock_teardown_cb
bt_accept_unlink
bt_sk(sk)->parent = NULL
release_sock(sk) ----------------> lock_sock(sk)
parent = /* NULL */
lock_sock(sk) <--------------------- release_sock(sk)
sock_set_flag(sk, SOCK_ZAPPED)
l2cap_sock_close_cb
l2cap_sock_kill(sk)
l2cap_sock_put_chan
chan = READ l2cap_pi(sk)->chan l2cap_pi(sk)->chan = NULL
l2cap_chan_hold_unless_zero l2cap_put_chan(chan)
kref_get_unless_zero(&chan->ref)
Task 1 may observe NULL which causes null-ptr-deref.
Fix the race by taking lock_sock() in l2cap_sock_kill() to
synchronize with l2cap_sock_cleanup_listen(). hold_unless_zero() is not
needed here, l2cap_pi(sk)->chan owns reference if it is non-NULL.
Clarify code comments vs. locking.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | b39298044e5534612511a2ff5de03ba5f6e7a820 |
| Linux | Linux | 8c37e4338c801ebb8cee52436c01c41e009f6e87 |
| Linux | Linux | 84e718b6a814edc84159361f9f454a4e92ae91ae |
| Linux | Linux | 36da806f7fbaee56ad9e81859deec203f9728700 |
| Linux | Linux | 6fef032af0092ed5ccb767239a9ac1bc38c08a40 |
| Linux | Linux | 6fef032af0092ed5ccb767239a9ac1bc38c08a40 |
| Linux | Linux | 733e76e74e406c1d1ddc7369420dd8a47f48bb8a |
| Linux | Linux | 6.1.178 |
| Linux | Linux | 6.6.145 |
| Linux | Linux | 6.12.97 |
| Linux | Linux | 6.18.40 |
| Linux | Linux | 7.1.5 |
| Linux | Linux | 7.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |