CVE-2026-98297: Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcicore: Fix queuing txwork after workqueue is drained
hcisendacl(), hcisendsco() and hcisendiso() queue hdev->txwork unconditionally. They can run from the L2CAP/SCO/ISO socket send path while hcidevclosesync() is draining hdev->workqueue (HCIDEVDOWN racing with a socket write). Since that queuework() is not chained work from the txwork worker itself, queuework() sees the queue marked WQDRAINING, warns "cannot queue %ps on wq %s", and drops the work:
WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 queuework Call Trace: queueworkon l2capchansend l2capsocksendmsg ...
hcidevclosesync() already sets HCICMDDRAINWORKQUEUE before draining, but only hcicmdwork() and handlecmdcntandtimer() check it before queuing. Route the txwork producers through the same guard via a shared hcischedtx() helper.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Route hci_send_acl(), hci_send_sco(), and hci_send_iso() tx_work producers through a shared hci_sched_tx() helper that checks HCI_CMD_DRAIN_WORKQUEUE before queueing work.