HIGH Introduced in 5.15
rfcomm ListenCleanup Deadlock
CVE-2026-98290
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI4.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock. Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt_accept_dequeue() locks the child while unlinking it and clearing its parent pointer. Dropping the child lock makes it important to prevent a concurrent rfcomm_connect_ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT_CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm_connect_ind() then rejects new children once cleanup starts.
02KernelScan AI Analysis
Risk summary
A lock ordering inversion in the Bluetooth RFCOMM listener cleanup path can deadlock the kernel when a listening socket is shut down concurrently with RFCOMM worker activity. Any local user with Bluetooth socket access can trigger the shutdown side of the race without special privileges. The resulting deadlock hangs the kernel, causing a system-wide denial of service.
Vulnerability analysis
When a listening Bluetooth RFCOMM socket is shut down, the cleanup path locks each child socket before locking the shared subsystem state, while a background worker locks those same resources in the opposite order. If both paths run at the same time, the kernel can deadlock. The fix changes the shutdown sequence so the listening socket is marked closed before its lock is released, then the queue is drained without holding the child locks. This prevents the inversion and also stops new connections from being added once cleanup starts. Any local user who can create Bluetooth sockets can trigger this, and the background worker can be active due to nearby Bluetooth devices or local Bluetooth activity.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 5.15 | 5.15.222 | eb4adaa46e4c |
| 6.1 | 5.15 | 6.1.189 | 4aafb47301a7 |
| 6.6 | 5.15 | 6.6.158 | c741977e413f |
| 6.12 | 5.15 | 6.12.112 | c6792c441767 |
| 6.18 | 5.15 | 6.18.54 | bfce253f039e |
| 7.2 | 5.15 | 7.2.8 | 18174b166547 |
| mainline | 5.15 | 7.3-rc4 | 801fb950cae7 |