Race condition in Linux kernel - CVE-2026-98109
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a kernel DEBUG_LOCKS warning.
The vulnerability exists due to a race condition in Bluetooth HCI device registration and Microsoft extension initialization when registering a Bluetooth device marked with an unconfigured-device quirk. A local user can trigger concurrent power-on work processing before the Microsoft extension mutex is initialized to trigger a kernel DEBUG_LOCKS warning.