PT-2026-98771 · Linux · Linux Kernel

CVE-2026-98109

·

Published

2026-09-25

·

Updated

2026-09-30

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists during Bluetooth device registration. In the hci register dev() function, the power-on work item is queued before the initialization of hdev->adv monitors idr and the registration of the MSFT extension via msft register(). For devices with specific quirks like HCI QUIRK RAW DEVICE, the HCI UNCONFIGURED flag is set. If the power-on work item runs concurrently on another CPU, hci power on() may trigger hci dev do close(), which subsequently calls msft do close().
Simultaneously, msft register() may allocate the msft structure and assign it to hdev->msft data before mutex init(&msft->filter lock) is called. If msft do close() executes while hdev->msft data is assigned but the mutex is not yet initialized, mutex lock(&msft->filter lock) will operate on an uninitialized mutex, leading to a system warning or instability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-104412
CVE-2026-98109

Affected Products

Linux Kernel