KernelScan.io

HIGH Introduced in 5.15

rfcomm ListenCleanup Deadlock

CVE-2026-98290

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI4.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock. Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt_accept_dequeue() locks the child while unlinking it and clearing its parent pointer. Dropping the child lock makes it important to prevent a concurrent rfcomm_connect_ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT_CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm_connect_ind() then rejects new children once cleanup starts.

02

Engine v0.7.0

Risk summary

A lock ordering inversion in the Bluetooth RFCOMM listener cleanup path can deadlock the kernel when a listening socket is shut down concurrently with RFCOMM worker activity. Any local user with Bluetooth socket access can trigger the shutdown side of the race without special privileges. The resulting deadlock hangs the kernel, causing a system-wide denial of service.

Affectednet/bluetooth/rfcomm/sock.c (Bluetooth RFCOMM)

Vulnerability analysis

When a listening Bluetooth RFCOMM socket is shut down, the cleanup path locks each child socket before locking the shared subsystem state, while a background worker locks those same resources in the opposite order. If both paths run at the same time, the kernel can deadlock. The fix changes the shutdown sequence so the listening socket is marked closed before its lock is released, then the queue is drained without holding the child locks. This prevents the inversion and also stops new connections from being added once cleanup starts. Any local user who can create Bluetooth sockets can trigger this, and the background worker can be active due to nearby Bluetooth devices or local Bluetooth activity.

03

BranchIntroducedFixed inPatch commit
5.155.155.15.222eb4adaa46e4c
6.15.156.1.1894aafb47301a7
6.65.156.6.158c741977e413f
6.125.156.12.112c6792c441767
6.185.156.18.54bfce253f039e
7.25.157.2.818174b166547
mainline5.157.3-rc4801fb950cae7