CVE-2026-53358

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously. The timeout handler already acquires conn->lock and chan->lock in the correct order. The timer is only armed when chan->conn is still set: if it is already NULL, l2cap_conn_del() has already processed this channel (l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb), so there is nothing left to do. If l2cap_conn_del() races in after the timer is armed, __clear_chan_timer() inside l2cap_chan_del() cancels it; if the timer has already fired, the handler returns harmlessly because chan->conn was cleared.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

History

22 Jul 2026, 19:07

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3634cbdc2eb414b69ffa752ddbe5e0458518e321 - () https://git.kernel.org/stable/c/3634cbdc2eb414b69ffa752ddbe5e0458518e321 - Patch
References () https://git.kernel.org/stable/c/50dfec218808b148ab4247b1858031b7a32015c5 - () https://git.kernel.org/stable/c/50dfec218808b148ab4247b1858031b7a32015c5 - Patch
References () https://git.kernel.org/stable/c/7555fd885a0603f50e49a655850a1f2bd8a25398 - () https://git.kernel.org/stable/c/7555fd885a0603f50e49a655850a1f2bd8a25398 - Patch
References () https://git.kernel.org/stable/c/859d3ace791ed878ae9ba5522c7844d960da8f88 - () https://git.kernel.org/stable/c/859d3ace791ed878ae9ba5522c7844d960da8f88 - Patch
References () https://git.kernel.org/stable/c/89dec92041717b027216e110599e4f6d6c921b79 - () https://git.kernel.org/stable/c/89dec92041717b027216e110599e4f6d6c921b79 - Patch
References () https://git.kernel.org/stable/c/8c8e620467a7b51562dbcefbd1f09f288d7d710d - () https://git.kernel.org/stable/c/8c8e620467a7b51562dbcefbd1f09f288d7d710d - Patch
References () https://git.kernel.org/stable/c/deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9 - () https://git.kernel.org/stable/c/deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9 - Patch
References () https://git.kernel.org/stable/c/e1c100e2d61bd8c718b7d91fe3e050780a9bf72d - () https://git.kernel.org/stable/c/e1c100e2d61bd8c718b7d91fe3e050780a9bf72d - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
CWE CWE-667
First Time Linux linux Kernel
Linux

18 Jul 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

02 Jul 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-02 15:17

Updated : 2026-07-22 19:07


NVD link : CVE-2026-53358

Mitre link : CVE-2026-53358

CVE.ORG link : CVE-2026-53358


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-667

Improper Locking