CVE-2026-98297
Received
Received - Intake
Bluetooth Stack TX Work Queue Issue in Linux Kernel
Vulnerability report for CVE-2026-98297, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work
unconditionally. They can run from the L2CAP/SCO/ISO socket send path
while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN
racing with a socket write). Since that queue_work() is not chained
work from the tx_work worker itself, __queue_work() sees the queue
marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops
the work:
WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
Call Trace:
queue_work_on
l2cap_chan_send
l2cap_sock_sendmsg
...
hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before
draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()
check it before queuing. Route the tx_work producers through the
same guard via a shared hci_sched_tx() helper.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9 |
| Linux | Linux | 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e |
| Linux | Linux | 525daaea459fc215f432de1b8debbd9144bf97b0 |
| Linux | Linux | 525daaea459fc215f432de1b8debbd9144bf97b0 |
| Linux | Linux | 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff |
| Linux | Linux | 6.12.93 |
| Linux | Linux | 6.18.35 |
| Linux | Linux | 7.0.12 |
| Linux | Linux | 7.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |