REDHAT-BUG-2320594: Low severity linux kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: FIX possible deadlock in rfcommskstatechange
rfcommskstatechange attempts to use socklock so it must never be called with it locked but rfcommsockioctl always attempt to lock it causing the following trace:
====================================================== WARNING: possible circular locking dependency detected 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Not tainted ------------------------------------------------------ syz-executor386/5093 is trying to acquire lock: ffff88807c396258 (sklock-AFBLUETOOTH-BTPROTORFCOMM){+.+.}-{0:0}, at: locksock include/net/sock.h:1671 [inline] ffff88807c396258 (sklock-AFBLUETOOTH-BTPROTORFCOMM){+.+.}-{0:0}, at: rfcommskstatechange+0x5b/0x310 net/bluetooth/rfcomm/sock.c:73
but task is already holding lock: ffff88807badfd28 (&d->lock){+.+.}-{3:3}, at: rfcommdlcclose+0x226/0x6a0 net/bluetooth/rfcomm/core.c:491
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2320594?
The severity of REDHAT-BUG-2320594 is considered high due to potential deadlock conditions.
How do I fix REDHAT-BUG-2320594?
To fix REDHAT-BUG-2320594, update the Linux kernel to the latest version that addresses this vulnerability.
What systems are affected by REDHAT-BUG-2320594?
REDHAT-BUG-2320594 affects systems running specific versions of the Linux kernel with Bluetooth RFCOMM capabilities.
What type of vulnerability is REDHAT-BUG-2320594?
REDHAT-BUG-2320594 is a deadlock vulnerability related to improper locking in Bluetooth RFCOMM operations.
Is there a workaround for REDHAT-BUG-2320594?
There is no recommended workaround for REDHAT-BUG-2320594; the best solution is to apply the kernel update.