CVE-2026-98246
Received Received - Intake

Use-After-Free in Linux Kernel Bluetooth Stack

Vulnerability report for CVE-2026-98246, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Serialize local codec list cleanup hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock. Codec list additions and both traversals in sco_sock_getsockopt() use that lock, but the close path does not. A close and BT_CODEC query can therefore interleave as follows: hci_dev_close_sync() sco_sock_getsockopt() hci_dev_lock() fetch codec entry hci_codec_list_clear() kfree(entry) read entry->id The reader then accesses an entry which the close path has freed. KASAN BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0 Read of size 1 at addr ffff8881001c3450 Call Trace: sco_sock_getsockopt+0xfa0/0xfe0 do_sock_getsockopt+0x537/0x7b0 __sys_getsockopt+0xf2/0x170 Allocated by task 92: hci_codec_list_add.isra.0+0x2c/0x440 hci_read_codec_capabilities+0x224/0x590 hci_read_supported_codecs+0x2c2/0x640 Freed by task 92: kfree+0x131/0x3c0 hci_codec_list_clear+0xd8/0x160 hci_dev_close_sync+0x92a/0xfa0 Take hdev->lock around the clear operation at its existing point in the close path. This makes the clear wait for active readers and prevents a new traversal until the list is empty without changing teardown ordering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
Linux Linux 6.1.57
Linux Linux 6.5.7
Linux Linux 6.6
Linux Linux 626535077ba9dc110787540d1fe24881094c15a1
Linux Linux b938790e70540bf4f2e653dcd74b232494d06c8f
Linux Linux b938790e70540bf4f2e653dcd74b232494d06c8f
Linux Linux b938790e70540bf4f2e653dcd74b232494d06c8f
Linux Linux b938790e70540bf4f2e653dcd74b232494d06c8f
Linux Linux b938790e70540bf4f2e653dcd74b232494d06c8f
Linux Linux eea5a8f0c3b7c884d2351e75fbdd0a3d7def5ae1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem. It occurs when the hci_dev_close_sync() function clears the local codec list without properly synchronizing with concurrent reads. A race condition allows a close operation to free a codec entry while another thread is still accessing it via sco_sock_getsockopt(), leading to a slab-use-after-free error.

Detection Guidance

This vulnerability is specific to the Linux kernel's Bluetooth subsystem and may not have direct network detection commands. Monitor kernel logs for slab-use-after-free errors related to sco_sock_getsockopt or hci_dev_close_sync. Check for crashes or memory corruption during Bluetooth operations.

Impact Analysis

This vulnerability could cause system crashes or instability when Bluetooth operations are performed concurrently with socket operations querying codec information. An attacker might exploit this to trigger kernel memory corruption, potentially leading to denial-of-service conditions or privilege escalation.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If immediate patching is not possible, restrict Bluetooth functionality or disable affected Bluetooth services until the fix is applied. Monitor system logs for signs of exploitation or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98246. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart