{"id":"CVE-2026-98290","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which take…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which take…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < 4aafb47301a799d3e01230d6568c4e93524e1523","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < c741977e413f5b49d306700820fb55ccb8269f5a","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < c6792c441767256030606eb82dca5d5fc360dd9a","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < bfce253f039eb5f58b810af267942a9f59207254","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < 18174b166547ef41973cc19feb5ef9cab39a8def","Linux >= b7ce436a5d798bc59e71797952566608a4b4626b < 801fb950cae7048eb7d83b18857d1ca37b8cd5a4","Linux 5.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:19.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98290","references":[{"url":"https://git.kernel.org/stable/c/18174b166547ef41973cc19feb5ef9cab39a8def","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4aafb47301a799d3e01230d6568c4e93524e1523","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/801fb950cae7048eb7d83b18857d1ca37b8cd5a4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfce253f039eb5f58b810af267942a9f59207254","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6792c441767256030606eb82dca5d5fc360dd9a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c741977e413f5b49d306700820fb55ccb8269f5a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.417Z","slug":"CVE-2026-98290","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which takes the child socket lock before\nrfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these\nlocks in reverse order while handling connections and DLC state changes,\nso lockdep reports a possible deadlock.\n\nClose dequeued children without taking their socket lock. The accept queue\nowns a reference to each child, and bt_accept_dequeue() locks the child\nwhile unlinking it and clearing its parent pointer.\n\nDropping the child lock makes it important to prevent a concurrent\nrfcomm_connect_ind() from enqueueing a new child after cleanup observes an\nempty queue. Set a listening socket to BT_CLOSED while its lock is still\nheld, before dropping the lock and draining the queue. The state check in\nrfcomm_connect_ind() then rejects new children once cleanup starts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}