In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
l2capchantimeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is running or pending, chan->conn can be freed, leading to a use-after-free when the timer worker attempts to lock conn->lock:
| BUG: KASAN: slab-use-after-free in instrumentatomicreadwrite include/linux/instrumented.h:112 [inline] | BUG: KASAN: slab-use-after-free in atomiclongtrycmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | BUG: KASAN: slab-use-after-free in __mutextrylockfast kernel/locking/mutex.c:161 [inline] | BUG: KASAN: slab-use-after-free in mutexlock+0x4f/0xa0 kernel/locking/mutex.c:318 | Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83 | | CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full) | Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 | Workqueue: events l2capchantimeout | Call Trace: | <TASK> | instrumentatomicreadwrite include/linux/instrumented.h:112 [inline] | atomiclongtrycmpxchgacquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | __mutextrylockfast kernel/locking/mutex.c:161 [inline] | mutexlock+0x4f/0xa0 kernel/locking/mutex.c:318 | l2capchantimeout+0x5d/0x1b0 net/bluetooth/l2capcore.c:422 | processonework kernel/workqueue.c:3326 [inline] | processscheduledworks+0x7c8/0xfb0 kernel/workqueue.c:3409 | workerthread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | retfromfork+0x1a3/0x470 arch/x86/kernel/process.c:158 | retfromforkasm+0x1a/0x30 arch/x86/entry/entry64.S:245 | </TASK> | | Allocated by task 320: | l2capconnadd+0xa7/0x820 net/bluetooth/l2capcore.c:7075 | l2capconnectcfm+0xdb/0xd70 net/bluetooth/l2capcore.c:7452 | hciconnectcfm include/net/bluetooth/hcicore.h:2139 [inline] | hciremotefeaturesevt+0x52f/0x9f0 net/bluetooth/hcievent.c:3760 | hcieventfunc net/bluetooth/hcievent.c:7796 [inline] | hcieventpacket+0x561/0xa70 net/bluetooth/hcievent.c:7847 | hcirxwork+0x370/0x890 net/bluetooth/hcicore.c:4040 | processonework kernel/workqueue.c:3326 [inline] | processscheduledworks+0x7c8/0xfb0 kernel/workqueue.c:3409 | workerthread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | retfromfork+0x1a3/0x470 arch/x86/kernel/process.c:158 | retfromforkasm+0x1a/0x30 arch/x86/entry/entry64.S:245 | | Freed by task 322: | hcidisconncfm include/net/bluetooth/hcicore.h:2154 [inline] | hciconnhashflush+0x101/0x1f0 net/bluetooth/hciconn.c:2736 | hcidevclosesync+0x889/0xde0 net/bluetooth/hcisync.c:5405 | hcidevdoclose net/bluetooth/hcicore.c:502 [inline] | hciunregisterdev+0x1f7/0x370 net/bluetooth/hcicore.c:2679 | vhcirelease+0x12a/0x180 drivers/bluetooth/hcivhci.c:690 | __fput+0x369/0x890 fs/filetable.c:510 | taskworkrun+0x160/0x1d0 kernel/taskwork.c:233 | getsignal+0xf5b/0x1120 kernel/signal.c:2810 | archdosignalor_restart+0x4d/0x600 arch/x86/kernel/signal.c:337 | _exittousermodeloop kernel/entry/common.c:64 [inline] | exittousermodeloop+0x85/0x510 kernel/entry/common.c:98 | dosyscall64+0x263/0x3d0 arch/x86/entry/syscall64.c:100 | entrySYSCALL64afterhwframe+0x77/0x7f | | The buggy address belongs to the object at ffff8881298d9400 | which belongs to the cache kmalloc-512 of size 512 | The buggy address is located 336 bytes inside of | freed 512-byte region [ffff8881298d9400, ffff8881298d9600)
Fix it by having chan->conn hold a reference to l2capconn (via l2capconnget) when the channel is added to the connection, and releasing it in the channel destructor. This ensures the l2capconn remains alive as long as the channel exists.
A new FLAG_DEL channel flag is introduced to indicate that the ch ---truncated---
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64434.json"
}