CVE-2026-98246

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Serialize local codec list cleanup hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock. Codec list additions and both traversals in sco_sock_getsockopt() use that lock, but the close path does not. A close and BT_CODEC query can therefore interleave as follows: hci_dev_close_sync() sco_sock_getsockopt() hci_dev_lock() fetch codec entry hci_codec_list_clear() kfree(entry) read entry->id The reader then accesses an entry which the close path has freed. KASAN BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0 Read of size 1 at addr ffff8881001c3450 Call Trace: sco_sock_getsockopt+0xfa0/0xfe0 do_sock_getsockopt+0x537/0x7b0 __sys_getsockopt+0xf2/0x170 Allocated by task 92: hci_codec_list_add.isra.0+0x2c/0x440 hci_read_codec_capabilities+0x224/0x590 hci_read_supported_codecs+0x2c2/0x640 Freed by task 92: kfree+0x131/0x3c0 hci_codec_list_clear+0xd8/0x160 hci_dev_close_sync+0x92a/0xfa0 Take hdev->lock around the clear operation at its existing point in the close path. This makes the clear wait for active readers and prevents a new traversal until the list is empty without changing teardown ordering.

Package Linux Kernel
Published 2026-10-06
Last modified 2026-10-06
Patch available
Yes

Affected versions

Linux kernel versions 6.1.57, 6.5.7, 6.6 and later are affected. Fixed in 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, 7.3-rc4 and their respective stable series.

Affected from
≥ 6.1.57 ≥ 6.5.7 ≥ 6.6
Fixed in
✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.112 6.12.x ✓ 6.18.54 6.18.x ✓ 7.2.8 7.2.x ✓ 7.3-rc4

Frequently asked questions

  • What is CVE-2026-98246?

    CVE-2026-98246 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.1.57 onward and has been patched in 6.1.189, 6.6.158, 6.12.112 and others. CVE-2026-98246 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98246?

    Yes. CVE-2026-98246 has been patched. Fixed versions include 6.1.189, 6.6.158, 6.12.112 and others. If you are running Linux kernel 6.1.57 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98246 actively exploited?

    No. CVE-2026-98246 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.