Deadlock in Linux kernel - CVE-2026-98290
Published: October 7, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to lock order inversion in rfcomm_sock_cleanup_listen() when closing unaccepted child sockets concurrently with RFCOMM worker activity. A local user can initiate shutdown of an RFCOMM listening socket while the worker handles connections or DLC state changes to cause a denial of service.
Affected software
How to mitigate CVE-2026-98290
External References
- https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def
- https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523
- https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4
- https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254
- https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a
- https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a
- https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c