Back to overview

CVE-2026-64206

Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pending_rx() takes the same mutex, so teardown can deadlock against the worker it is flushing. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the l2cap_conn_ready() -> queue_work(..., &conn->pending_rx_work) submit path, the l2cap_conn_del() -> cancel_work_sync(&conn->pending_rx_work) teardown path, and the process_pending_rx() -> mutex_lock(&conn->lock) worker edge. Lockdep WARNING: possible circular locking dependency detected process_pending_rx+0x21/0x2a [vuln_msv] l2cap_conn_del.constprop.0+0x3f/0x4e [vuln_msv] *** DEADLOCK *** Cancel pending_rx_work before taking conn->lock, matching the existing lock-before-drain ordering used for the two delayed works in the same teardown path. The pending_rx queue is still purged after the work has been cancelled and conn->lock has been acquired.

Metadata

CVE ID
CVE-2026-64206
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-20 16:27 UTC
Last updated
2026-07-20 16:27 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 7ab56c3a6eccb215034b0cb096e0313441cbf2a4 < d5616beb3355b5fca2280d796c1cf7ada4ee6551, 7ab56c3a6eccb215034b0cb096e0313441cbf2a4 < e96fbac8d3a73b0bc165383c092a30628561d320, 7ab56c3a6eccb215034b0cb096e0313441cbf2a4 < 2641a9e0a1dd4af2e21995470a21d55dd35e5203, ee805f9499ebd0edf0877990968543c752043b59 …
Linux Linux 3.16, 0 < 3.16, 6.18.39 ≤ 6.18.*, 7.1.4 ≤ 7.1.* …
Back to overview