CVE-2026-53256 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock, but returns the selected listener after dropping that lock without taking a reference. rfcomm_connect_ind() then locks the listener, queues a child socket on it, and may notify it after unlocking it. The buggy scenario involves two paths, with each column showing the order within that path: rfcomm_connect_ind(): listener close: 1. Find parent in 1. close() enters rfcomm_get_sock_by_channel() rfcomm_sock_release(). 2. Drop rfcomm_sk_list.lock 2. rfcomm_sock_shutdown() without pinning parent. closes the listener. 3. Call lock_sock(parent) and 3. rfcomm_sock_kill() bt_accept_enqueue(parent, unlinks and puts parent. sk, true). 4. Read parent flags and may 4. parent can be freed. call sk_state_change(). If close wins the race, parent can be freed before rfcomm_connect_ind() reaches lock_sock(), bt_accept_enqueue(), or the deferred-setup callback. Take a reference on the listener before leaving rfcomm_sk_list.lock. After lock_sock() succeeds, recheck that it is still in BT_LISTEN before queueing a child, cache the deferred-setup bit while the parent is locked, and drop the reference after the last parent use. KASAN reported a slab-use-after-free in lock_sock_nested() from rfcomm_connect_ind(), with the freeing stack going through rfcomm_sock_kill() and rfcomm_sock_release().
A use-after-free vulnerability has been identified in the Bluetooth RFCOMM implementation of the Linux kernel. This issue arises in the 'rfcomm_connect_ind()' function, which handles incoming connection indications. The vulnerability occurs because 'rfcomm_get_sock_by_channel()' returns a listener socket without retaining a reference, after dropping the list lock. Consequently, the listener can be closed and freed before it is properly used, leading to a use-after-free condition. The Kernel Address Sanitizer (KASAN) detected this memory corruption issue, which can be exploited to cause a denial-of-service or potentially execute arbitrary code.
Users can upgrade to the patched version of the Linux kernel available in the official Linux Git repository. Instructions for downloading the latest version can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1f73f92f66251065a5f39b09a47cf05ea14d3107 | kernel.org | Patch |
| https://git.kernel.org/stable/c/43c441edacf953b39517a44f5e5e10a93618b226 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6f4462d12133106460d7c046b95aad2491e3fddf | kernel.org | Patch |
| https://git.kernel.org/stable/c/8802413ce63175fb522a2bd609fb043a3550c720 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a07d741c077d4e34b16458241a94d29039386553 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b0e33e409715c617e2a20f46f99aa5403a14dfda | kernel.org | Patch |
| https://git.kernel.org/stable/c/de31973ef00e5aa55496f84cf6a44bb157a34e02 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f5ec76bdbeb80f75ad0be204371afffee0f8fac8 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 25, 2026 | New CVE Received | kernel.org |