Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth subsystem (BNEP) that could lead to a system crash. When a Bluetooth network connection is being set up, a race condition allows the underlying connection to be deleted while the system is still trying to register it. This results in the system attempting to access memory that has already been freed, potentially causing a kernel panic or instability.
Technical details
A race condition exists in net/bluetooth/bnep/core.c within the bnep_add_connection() function. The function reads the L2CAP connection without holding the necessary channel lock before passing the HCI device to register_netdev(). If a controller teardown occurs concurrently, the connection can be released, leading to a null pointer dereference or use-after-free when the registration path attempts to access the freed parent device. The fix involves properly pinning the L2CAP connection by taking a reference while holding the channel lock and retaining it until registration is complete.
Affected products
- Linux Linux Kernel 3.13 to 6.10.x
Timeline
- 2026-06-28: other: Patch submitted by developer
- 2026-07-24: patched: Patch committed to stable tree
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/390b5db3ff8745187f094c4e915663b7b1f98944
- https://git.kernel.org/stable/c/46a88784c4c9b96954dd86f747ce93f65efa1302
- https://git.kernel.org/stable/c/551ae773ec64045b4e72099132654887e0270bcc
- https://git.kernel.org/stable/c/563a8573047182f550b1e1e030615755cd8c41da
- https://git.kernel.org/stable/c/a6b22dbd80926556290ad2243be25218d6956a19
- https://git.kernel.org/stable/c/ae215c5b6422d8eda443b861b124bd1be6969c31
- https://git.kernel.org/stable/c/bb067a99a0356196c0b89a95721985485ebce5a5