CVE-2026-98246: Bluetooth: hci_sync: Serialize local codec list cleanup
Bluetooth: hcisync: Serialize local codec list cleanup
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the Linux kernel Bluetooth HCI close path, take hdev->lock around the hci_dev_close_sync() operation that clears hdev->local_codecs, serializing codec-list cleanup with readers and preventing a new close path from starting during active traversals.
Event History
Frequently Asked Questions
What conditions are required to trigger the issue?
A Bluetooth device close operation must overlap with a BT_CODEC query through sco_sock_getsockopt(). The query can fetch a codec-list entry while the close path frees that entry.
Which code path is exposed to the use-after-free?
The affected reader is sco_sock_getsockopt(), which traverses the local codec list under hdev->lock. The unsafe concurrent writer is hci_dev_close_sync(), which previously cleared that list after releasing the lock.
How can an affected system be recognized?
KASAN may report a slab-use-after-free in sco_sock_getsockopt, including a read of a codec entry after hci_codec_list_clear freed it. The reported call trace includes sco_sock_getsockopt, do_sock_getsockopt, and __sys_getsockopt.
What does the fix change?
The fix takes hdev->lock around local codec list cleanup at the existing point in the device close path. This makes cleanup wait for active readers and prevents new traversals until the list is empty.