PT-2026-106619 · Linux · Linux
CVE-2026-98290
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
rfcomm sock cleanup listen() closes unaccepted child sockets through
rfcomm sock close(), which takes the child socket lock before
rfcomm dlc close() acquires rfcomm mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt accept dequeue() locks the child
while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent
rfcomm connect ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm connect ind() then rejects new children once cleanup starts.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux