CVE-2026-98290
Received Received - Intake

Bluetooth RFCOMM Socket Lock Inversion Vulnerability

Vulnerability report for CVE-2026-98290, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock. Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt_accept_dequeue() locks the child while unlinking it and clearing its parent pointer. Dropping the child lock makes it important to prevent a concurrent rfcomm_connect_ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT_CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm_connect_ind() then rejects new children once cleanup starts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux b7ce436a5d798bc59e71797952566608a4b4626b
Linux Linux 5.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the Bluetooth RFCOMM subsystem. It involves a potential deadlock due to incorrect lock ordering between socket cleanup and connection handling. The issue occurs when cleaning up unaccepted child sockets, which can lead to a circular dependency in lock acquisition and cause the system to hang.

Detection Guidance

This vulnerability is specific to the Linux kernel's Bluetooth RFCOMM implementation and may not have direct network detection commands. Monitor kernel logs for lockdep warnings related to Bluetooth socket operations. Check for kernel messages indicating socket lock inversions or deadlocks in Bluetooth subsystems.

Impact Analysis

If exploited, this vulnerability could cause system hangs or crashes in the Linux kernel when Bluetooth RFCOMM connections are active. Users might experience Bluetooth functionality failures, system freezes, or denial-of-service conditions affecting the entire system.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this vulnerability. If immediate patching is not possible, consider disabling the Bluetooth RFCOMM protocol if not required, or restrict Bluetooth functionality to trusted devices only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart