CVE-2026-90092
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90092, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-18

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN New sk should not be added to parent socket accept queue after last l2cap_sock_cleanup_listen() has run in l2cap_sock_teardown_cb() and state set to BT_CLOSED, as that can result to UAF on dereferencing the dangling parent reference. l2cap_sock_new_connection_cb() may race with parent l2cap_chan teardown, due to chan->state accessed without consistent locking: [Task 1] [Task 2] l2cap_sock_release(parent) l2cap_connect l2cap_sock_shutdown pchan = l2cap_global_chan_by_psm l2cap_chan_lock(pchan) l2cap_chan_close l2cap_sock_teardown_cb pchan->state = BT_CLOSED l2cap_chan_unlock(pchan) ------> l2cap_chan_lock(pchan) l2cap_new_connection l2cap_sock_new_connection_cb l2cap_chan_lock(pchan) <-------- l2cap_chan_unlock(pchan) l2cap_sock_kill(parent) /* bt_sk(sk)->parent dangling */ Fix by adding check for sk_state == BT_LISTEN after acquiring sk lock in l2cap_sock_new_connection_cb(). Add lock_sock() around sk_state writes where missing, to avoid data races. Although the data races on pchan->state should be fixed too, this defensive sk_state check probably makes sense in any case.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-18
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
Linux Linux 0c17c8832562b2aac288e89cefd0f46074f54bcb
Linux Linux 5105f3e6b2df619c635b5f6a49fac131a36c7952
Linux Linux c88c185ae0a1067823661b220aeea613df2c127b
Linux Linux 1810e42ff6716f320c7269d5850eca48b07b7427
Linux Linux 2ff1a41a912de8517b4482e946dd951b7d80edbf
Linux Linux 2ff1a41a912de8517b4482e946dd951b7d80edbf
Linux Linux 1b1c0da227bf63479bac9982fc8d12df9aaea0fb
Linux Linux 85426e97dc72f2088ba6d27e74cd58c3fbd43e31
Linux Linux a2dcf1a61d056aef15b63c6eae9441344d624389
Linux Linux 6.1.175
Linux Linux 6.6.140
Linux Linux 6.12.88
Linux Linux 6.18.30
Linux Linux 5.10.258
Linux Linux 5.15.209
Linux Linux 7.0.7
Linux Linux 7.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90092. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart