PT-2026-94440 · Linux · Linux Kernel
CVE-2026-90092
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A Use-After-Free (UAF) issue exists in the Bluetooth L2CAP implementation. The problem occurs because a new socket may be added to the parent socket accept queue after the
l2cap sock cleanup listen() function has executed within l2cap sock teardown cb() and the state has been set to BT CLOSED. This happens due to a race condition in the l2cap sock new connection cb() function during parent l2cap chan teardown, caused by inconsistent locking when accessing chan->state. This can lead to the dereferencing of a dangling parent reference.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel