SB2026100775 - Deadlock in Linux kernel bluetooth rfcomm
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deadlock (CVE-ID: CVE-2026-98290)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to lock order inversion in rfcomm_sock_cleanup_listen() when closing unaccepted child sockets concurrently with RFCOMM worker activity. A local user can initiate shutdown of an RFCOMM listening socket while the worker handles connections or DLC state changes to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def
- https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523
- https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4
- https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254
- https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a
- https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a
- https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c