EN

Tracker / CVE-2026-53071

CVE-2026-53071

Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().

Prodotti e versioni affette

linux linux_kernel · 5.11 → 5.15.209
linux linux_kernel · 5.16 → 6.1.175
linux linux_kernel · 5.7 → 5.10.258
linux linux_kernel · 6.13 → 6.18.33
linux linux_kernel · 6.19 → 7.0.10
linux linux_kernel · 6.2 → 6.6.141
linux linux_kernel · 6.7 → 6.12.91

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti