SB2026040664 - Use-after-free in Linux kernel bluetooth
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-23461)
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in l2cap_unregister_user when accessing conn->users and conn->hchan concurrently with l2cap_conn_del(). A local attacker can trigger a race condition to cause a denial of service.
The issue is caused by inconsistent locking on the l2cap_conn structure and may also result in list corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/11a87dd5df428a4b79a84d2790cac7f3c73f1f0d
- https://git.kernel.org/stable/c/71030f3b3015a412133a805ff47970cdcf30c2b8
- https://git.kernel.org/stable/c/752a6c9596dd25efd6978a73ff21f3b592668f4a
- https://git.kernel.org/stable/c/c22a5e659959eb77c2fbb58a5adfaf3c3dab7abf
- https://git.kernel.org/stable/c/da3000cbe4851458a22be38bb18c0689c39fdd5f