Executive brief
The Linux kernel's Bluetooth 6LoWPAN component has a race condition where module cleanup can occur while asynchronous work is still accessing shared state. This can lead to kernel memory corruption and system instability. An attacker with local access to debugfs could trigger this flaw to cause a kernel crash or potential code execution.
Technical details
The vulnerability is a use-after-free race condition in the Bluetooth 6LoWPAN subsystem. The lowpan_enable_set() function schedules work asynchronously on the system work queue, but returns to debugfs immediately without synchronization. When module exit (bt_6lowpan_exit()) tears down shared state like listen_chan, the queued work item may still be executing and accessing freed memory, triggering a use-after-free. The fix converts the operation from asynchronous to synchronous within the debugfs setter, ensuring the entire operation completes before debugfs removal and module teardown. This vulnerability requires local access to the debugfs interface and can result in kernel panics or memory corruption.
Affected products
- Linux Linux kernel Unknown
Timeline
- 2026-08-15: disclosed