---
id: CVE-2024-36013
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()

  Extend a critical section to prevent chan from early freeing.
  Also make the l2cap_connect() return type vo…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()

  Extend a critical section to prevent chan from early freeing.
  Also make the l2cap_connect() return type vo…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 3.0, < 6.6.32'
  - 'linux_kernel >= 6.7, < 6.8.11'
  - linux_kernel = 6.9
patched:
  - linux_kernel 6.8.11
published: '2024-05-23'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-36013'
references:
  - url: 'https://git.kernel.org/stable/c/4d7b41c0e43995b0e992b9f8903109275744b658'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/826af9d2f69567c646ff46d10393d47e30ad23c6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8629a65a48890769c47ebc9b6e57c02a80a8975e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cfe560c7050bfb37b0d2491bbe7cd8b59e77fdc5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'http://www.openwall.com/lists/oss-security/2024/05/30/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/05/30/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/4d7b41c0e43995b0e992b9f8903109275744b658'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/826af9d2f69567c646ff46d10393d47e30ad23c6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/cfe560c7050bfb37b0d2491bbe7cd8b59e77fdc5'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00479
epssPercentile: 0.40533
ingestedAt: '2026-07-24T15:30:57.317Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()

Extend a critical section to prevent chan from early freeing.
Also make the l2cap_connect() return type void. Nothing is using the
returned value but it is ugly to return a potentially freed pointer.
Making it void will help with backports because earlier kernels did use
the return value. Now the compile will break for kernels where this
patch is not a complete fix.

Call stack summary:

[use]
l2cap_bredr_sig_cmd
  l2cap_connect
  ┌ mutex_lock(&conn->chan_lock);
  │ chan = pchan->ops->new_connection(pchan); <- alloc chan
  │ __l2cap_chan_add(conn, chan);
  │   l2cap_chan_hold(chan);
  │   list_add(&chan->list, &conn->chan_l);   ... (1)
  └ mutex_unlock(&conn->chan_lock);
    chan->conf_state              ... (4) <- use after free

[free]
l2cap_conn_del
┌ mutex_lock(&conn->chan_lock);
│ foreach chan in conn->chan_l:            ... (2)
│   l2cap_chan_put(chan);
│     l2cap_chan_destroy
│       kfree(chan)               ... (3) <- chan freed
└ mutex_unlock(&conn->chan_lock);

==================================================================
BUG: KASAN: slab-use-after-free in instrument_atomic_read
include/linux/instrumented.h:68 [inline]
BUG: KASAN: slab-use-after-free in _test_bit
include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]
BUG: KASAN: slab-use-after-free in l2cap_connect+0xa67/0x11a0
net/bluetooth/l2cap_core.c:4260
Read of size 8 at addr ffff88810bf040a0 by task kworker/u3:1/311

## Affected

- `linux_kernel >= 3.0, < 6.6.32`
- `linux_kernel >= 6.7, < 6.8.11`
- `linux_kernel = 6.9`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.8.11`
