Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64557

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/07/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()<br /> <br /> l2cap_sock_new_connection_cb() returned l2cap_pi(sk)-&gt;chan after<br /> release_sock(parent). Once the parent lock is dropped the newly<br /> enqueued child socket sk is reachable via the accept queue, so another<br /> task can accept and free it before the callback dereferences sk,<br /> resulting in a use-after-free.<br /> <br /> Rework the -&gt;new_connection() op so the core, rather than the callback,<br /> owns the child channel&amp;#39;s lifetime. The op now receives a pre-allocated<br /> new_chan and returns an errno instead of allocating and returning a<br /> channel. l2cap_new_connection() allocates the child channel and links<br /> it into the conn list via __l2cap_chan_add() before invoking the<br /> callback, so the conn-list reference keeps the channel alive once<br /> release_sock(parent) exposes the socket to other tasks.<br /> <br /> Channel configuration that was duplicated in l2cap_sock_init() and the<br /> various new_connection callbacks is consolidated into<br /> l2cap_chan_set_defaults(), which now inherits from the parent channel<br /> when one is supplied.