CVE-2026-23461
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in hci_chan_del"), l2cap_conn_del() uses conn->lock to protect access to conn->users. However, l2cap_register_user() and l2cap_unregister_user() don't use conn->lock, creating a race condition where these functions can access conn->users and conn->hchan concurrently with l2cap_conn_del().
This can lead to use-after-free and list corruption bugs, as reported by syzbot.
Fix this by changing l2cap_register_user() and l2cap_unregister_user() to use conn->lock instead of hci_dev_lock(), ensuring consistent locking for the l2cap_conn structure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.6.84,<6.6.130
- cpe:2.3:o:linux:linux_kernel:6.14:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.14:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.14:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.14:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.14:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.14:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
5- git.kernel.org/stable/c/11a87dd5df428a4b79a84d2790cac7f3c73f1f0dnvdPatch
- git.kernel.org/stable/c/71030f3b3015a412133a805ff47970cdcf30c2b8nvdPatch
- git.kernel.org/stable/c/752a6c9596dd25efd6978a73ff21f3b592668f4anvdPatch
- git.kernel.org/stable/c/c22a5e659959eb77c2fbb58a5adfaf3c3dab7abfnvdPatch
- git.kernel.org/stable/c/da3000cbe4851458a22be38bb18c0689c39fdd5fnvdPatch
News mentions
0No linked articles in our index yet.