SB20260919126 - Use-after-free in Linux kernel bluetooth
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-90092)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to a race condition in l2cap_sock_new_connection_cb when handling new L2CAP connections during parent L2CAP channel teardown. A remote attacker can initiate a new L2CAP connection while a parent socket is being torn down to trigger a use-after-free condition.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2a3a27aaf19bf069720e024ce6fde54e6bf80df9
- https://git.kernel.org/stable/c/491e4c60017969b053888029998d2a61f298986a
- https://git.kernel.org/stable/c/87276dc15b559d32757a43b4415c8445fbae06c4
- https://git.kernel.org/stable/c/bf61a65c6093970e3b50031c4b79ebf3bd411eba
- https://git.kernel.org/stable/c/c47339e169bf4a0a4cfabb91351471f67744c2bc
- https://git.kernel.org/stable/c/d4bfa78fd67929b62b02013c107973e0c5b7aa9a