Race condition in Linux kernel - CVE-2026-98297
Published: October 7, 2026
Vulnerability details
The vulnerability allows a local user to disrupt Bluetooth data transmission.
The vulnerability exists due to a race condition in the Bluetooth hci_send_acl(), hci_send_sco(), and hci_send_iso() functions when socket writes occur concurrently with HCI device shutdown and workqueue draining. A local user can trigger Bluetooth socket writes during workqueue draining to disrupt Bluetooth data transmission.