CVE 8.8 HIGH

Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp_CVE-2026-53071

8.8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp

l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding
l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file
acquires the lock first. A remote BLE device can send a crafted
L2CAP ECRED reconfiguration response to corrupt the channel list
while another thread is iterating it.

Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),
and l2cap_chan_unlock() and l2cap_chan_put() after, matching the
pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().

Basic Information

ID CVE-2026-53071
Source Linux
Published Jun 24, 2026 at 16:30
Modified Jun 28, 2026 at 06:38

Affected Product

Vendor Linux
Product Linux
Version 15f02b91056253e8cdc592888f431da0731337b8
Affected Versions Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux Linux 5.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.