CVE-2026-98246: Bluetooth: hci_sync: Serialize local codec list cleanup

Published Oct 6, 2026
·
Updated

Bluetooth: hcisync: Serialize local codec list cleanup

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the Linux kernel Bluetooth HCI close path, take hdev->lock around the hci_dev_close_sync() operation that clears hdev->local_codecs, serializing codec-list cleanup with readers and preventing a new close path from starting during active traversals.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:25 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required to trigger the issue?

A Bluetooth device close operation must overlap with a BT_CODEC query through sco_sock_getsockopt(). The query can fetch a codec-list entry while the close path frees that entry.

2

Which code path is exposed to the use-after-free?

The affected reader is sco_sock_getsockopt(), which traverses the local codec list under hdev->lock. The unsafe concurrent writer is hci_dev_close_sync(), which previously cleared that list after releasing the lock.

3

How can an affected system be recognized?

KASAN may report a slab-use-after-free in sco_sock_getsockopt, including a read of a codec entry after hci_codec_list_clear freed it. The reported call trace includes sco_sock_getsockopt, do_sock_getsockopt, and __sys_getsockopt.

4

What does the fix change?

The fix takes hdev->lock around local codec list cleanup at the existing point in the device close path. This makes cleanup wait for active readers and prevents new traversals until the list is empty.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203