Executive brief
A vulnerability in the Linux kernel's Bluetooth 6LoWPAN module can cause a system crash when a Bluetooth Low Energy connection is disconnected while a debugfs control command is being executed. An attacker with local access to debugfs could trigger the race condition to crash the kernel or potentially execute code, disrupting Bluetooth connectivity and system stability.
Technical details
This is a use-after-free vulnerability in the Bluetooth 6lowpan module caused by improper reference counting of L2CAP connections. The get_l2cap_conn() function retrieves an L2CAP connection reference under hdev lock protection but drops that lock before returning, creating a window where a concurrent HCI disconnect or device close can free the L2CAP connection. When lowpan_control_write() later dereferences the connection pointer via debugfs, it accesses freed memory. The fix involves holding an explicit L2CAP connection reference using l2cap_conn_hold_unless_zero() while under hdev protection and releasing it only after all debugfs operations complete. The vulnerability can be triggered by exploiting the race between a debugfs write operation and an HCI disconnect event.
Affected products
- Linux Linux kernel 5.0 and later (prior to fix in 2026-08-15)
Timeline
- 2026-08-15: disclosed: CVE-2026-72336 published
- 2026-08-15: patched: Kernel fix applied