๐Ÿ” CVE Alert

CVE-2026-98246

UNKNOWN 0.0

Bluetooth: hci_sync: Serialize local codec list cleanup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Serialize local codec list cleanup hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock. Codec list additions and both traversals in sco_sock_getsockopt() use that lock, but the close path does not. A close and BT_CODEC query can therefore interleave as follows: hci_dev_close_sync() sco_sock_getsockopt() hci_dev_lock() fetch codec entry hci_codec_list_clear() kfree(entry) read entry->id The reader then accesses an entry which the close path has freed. KASAN BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0 Read of size 1 at addr ffff8881001c3450 Call Trace: sco_sock_getsockopt+0xfa0/0xfe0 do_sock_getsockopt+0x537/0x7b0 __sys_getsockopt+0xf2/0x170 Allocated by task 92: hci_codec_list_add.isra.0+0x2c/0x440 hci_read_codec_capabilities+0x224/0x590 hci_read_supported_codecs+0x2c2/0x640 Freed by task 92: kfree+0x131/0x3c0 hci_codec_list_clear+0xd8/0x160 hci_dev_close_sync+0x92a/0xfa0 Take hdev->lock around the clear operation at its existing point in the close path. This makes the clear wait for active readers and prevents a new traversal until the list is empty without changing teardown ordering.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
626535077ba9dc110787540d1fe24881094c15a1 < 9f407d52c0d881430d689836d3e7d32aa36f98b5 b938790e70540bf4f2e653dcd74b232494d06c8f < 560ed4373c06a58123ecdf9ad5ecaddc87a73382 b938790e70540bf4f2e653dcd74b232494d06c8f < 1ee0c5429dc4a92879bda2554b1bfd4abc6c587c b938790e70540bf4f2e653dcd74b232494d06c8f < 4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00 b938790e70540bf4f2e653dcd74b232494d06c8f < 1276c2fafd18499769a28f96f45c5a76d6fc990e b938790e70540bf4f2e653dcd74b232494d06c8f < 9a10987a2f160a44a638c9a35994ca6e3089696e eea5a8f0c3b7c884d2351e75fbdd0a3d7def5ae1 6.1.57 < 6.1.189 6.5.7 < 6.6
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9f407d52c0d881430d689836d3e7d32aa36f98b5 git.kernel.org: https://git.kernel.org/stable/c/560ed4373c06a58123ecdf9ad5ecaddc87a73382 git.kernel.org: https://git.kernel.org/stable/c/1ee0c5429dc4a92879bda2554b1bfd4abc6c587c git.kernel.org: https://git.kernel.org/stable/c/4dc1ae5ff75b17e17ec4b74b11cc4b0099e71e00 git.kernel.org: https://git.kernel.org/stable/c/1276c2fafd18499769a28f96f45c5a76d6fc990e git.kernel.org: https://git.kernel.org/stable/c/9a10987a2f160a44a638c9a35994ca6e3089696e