CVE-2026-72336: Bluetooth: 6lowpan: hold L2CAP conn across debugfs control

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: 6lowpan: hold L2CAP conn across debugfs control

getl2capconn() looks up an LE hciconn under hdev protection, but then drops that protection before reading hcon->l2capdata and before lowpancontrolwrite() later dereferences conn->hcon. A disconnect or device close can tear down the same L2CAP connection in that window.

The buggy scenario involves two paths, with each column showing the order within that path:

6LoWPAN control write: HCI disconnect/device close: 1. getl2capconn() finds hcon 1. hcidisconncfm() dispatches and hcon->l2capdata. the L2CAP disconnect callback. 2. getl2capconn() drops hdev 2. l2capconndel() clears protection and returns conn. hcon->l2capdata and drops the L2CAP connection reference. 3. lowpancontrolwrite() reads 3. hciconndel() removes and drops conn->hcon. the HCI connection.

Take a reference to the L2CAP connection with l2capconnholdunlesszero() while hdev is still locked, and drop that reference after the debugfs command's last use of conn. This mirrors the existing L2CAP ACL receive-side handoff and keeps the connection dereferenceable after leaving hdev protection. Export the existing helper so the bluetooth6lowpan module can use the same lifetime primitive.

Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in lowpancontrolwrite+0x374/0x520 The buggy address belongs to the object at ffff888111b9d000 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 0 bytes inside of freed 1024-byte region [ffff888111b9d000, ffff888111b9d400) Read of size 8 Call trace: dumpstacklvl+0x66/0xa0 printreport+0xce/0x5f0 lowpancontrolwrite+0x374/0x520 (net/bluetooth/6lowpan.c:1131) srsoaliasreturnthunk+0x5/0xfbef5 virtaddrvalid+0x19f/0x330 kasanreport+0xe0/0x110 debugfsfileget+0xf7/0x400 fullproxywrite+0x9e/0xd0 vfswrite+0x1b0/0x810 ksyswrite+0xd2/0x170 dnotifyflush+0x32/0x220 dosyscall64+0x115/0x6a0 (arch/x86/entry/syscall64.c:87) entrySYSCALL64afterhwframe+0x77/0x7f Allocated by task stack: kasansavestack+0x33/0x60 kasansavetrack+0x17/0x60 kasankmalloc+0xaa/0xb0 l2capconnadd+0x45/0x520 l2capchanconnect+0xac6/0xd90 l2capsockconnect+0x216/0x350 sysconnect+0x101/0x130 x64sysconnect+0x40/0x50 dosyscall64+0x115/0x6a0 (arch/x86/entry/syscall64.c:87) entrySYSCALL64afterhwframe+0x77/0x7f Freed by task stack: kasansavestack+0x33/0x60 kasansavetrack+0x17/0x60 kasansavefreeinfo+0x3b/0x60 kasanslabfree+0x5f/0x80 kfree+0x313/0x590 hciconnhashflush+0xc0/0x140 hcidevclosesync+0x41a/0xb00 hcidevclose+0x12f/0x160 hcisockioctl+0x157/0x570 sockdoioctl+0xf7/0x210 sockioctl+0x32f/0x490 x64sysioctl+0xc7/0x110 dosyscall64+0x115/0x6a0 (arch/x86/entry/syscall64.c:87) entrySYSCALL64afterhwframe+0x77/0x7f kasanrecordauxstack+0xa7/0xc0 insertwork+0x32/0x100 queuework+0x262/0xa60 queueworkon+0xad/0xb0 l2capconnectcfm+0x4ef/0x670 hcileremotefeatcompleteevt+0x247/0x430 hcieventpacket+0x360/0x6f0 hcirxwork+0x2ae/0x7a0 processonework+0x4fd/0xbc0 workerthread+0x2d8/0x570 kthread+0x1ad/0x1f0 retfromfork+0x3c9/0x540 retfromforkasm+0x1a/0x30

Event History

Aug 15, 2026
CVE Published
via MITRE·05:55 AM
Data Sourced
via MITRE·05:55 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203