PT-2026-106619 · Linux · Linux

CVE-2026-98290

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
rfcomm sock cleanup listen() closes unaccepted child sockets through rfcomm sock close(), which takes the child socket lock before rfcomm dlc close() acquires rfcomm mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt accept dequeue() locks the child while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent rfcomm connect ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm connect ind() then rejects new children once cleanup starts.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98290

Affected Products

Linux