CVE-2026-90093

HIGHCVSS 7.8/10

Last modified

CVE-2026-90093 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg.

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in l2cap_sock_setsockopt() access of conn->hcon->hdev. Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in getsockopt/setsockopt to ensure it stays alive, and to avoid data races in l2cap_chan fields.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b66774b48dd98f07254951f74ea6f513efe7ff8b, < f49321c85785178214fd67f2e9b4b73d6363783b; >= b66774b48dd98f07254951f74ea6f513efe7ff8b, < ca2c4c26498643f421d35ffe258fafbd3ed461c3; 8f90405a4a6f1f1880dc07996b47bf57c712bd8a; 32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b; 8922c7940bae9ce4b1736dddb6362370793835c2; 91047a4396a8b1857a6f712a90cf33ec0012b189; 0b0e2bf39cf99e458d991b9df253727e036a7d7d; d3b739db5dc6f688a60d56da872fabaf65246032; 50c38d9f42a529691e4e67ea9cedf4f0bfc8d277; >= 5.10.265, < 5.11; >= 5.15.216, < 5.16; >= 6.1.183, < 6.2; >= 6.6.145, < 6.7; >= 6.12.97, < 6.13; >= 6.18.39, < 6.19; >= 7.1.4, < 7.2
LinuxLinux7.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90093?
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in l2cap_sock_setsockopt() access of conn->hcon->hdev. Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in getsockopt/setsockopt to ensure it stays alive, and to avoid data races in l2cap_chan fields.
How severe is CVE-2026-90093?
CVE-2026-90093 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-90093?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90093?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST