cbcvebase.
CVE-2024-26886
published 2024-04-17

CVE-2024-26886: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a…

PriorityP423medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.49%
39.7th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a deadlock as shown bellow, so instead of using sock_sock this uses sk_receive_queue.lock on bt_sock_ioctl to avoid the UAF: INFO: task kworker/u9:1:121 blocked for more than 30 seconds. Not tainted 6.7.6-lemon #183 Workqueue: hci0 hci_rx_work Call Trace: __schedule+0x37d/0xa00 schedule+0x32/0xe0 __lock_sock+0x68/0xa0 ? __pfx_autoremove_wake_function+0x10/0x10 lock_sock_nested+0x43/0x50 l2cap_sock_recv_cb+0x21/0xa0 l2cap_recv_frame+0x55b/0x30a0 ? psi_task_switch+0xeb/0x270 ? finish_task_switch.isra.0+0x93/0x2a0 hci_rx_work+0x33a/0x3f0 process_one_work+0x13a/0x2f0 worker_thread+0x2f0/0x410 ? __pfx_worker_thread+0x10/0x10 kthread+0xe0/0x110 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x2c/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1d576c3a5af850bf11fbd103f9ba11aa6d6061fb < 64be3c6154886200708da0dfe259705fb992416c64be3c6154886200708da0dfe259705fb992416c
linuxlinux>= 2b16d960c79abc397f102c3d23d30005b68cb036 < 60673f442984fe689d4127a5dd4be414247b3d6760673f442984fe689d4127a5dd4be414247b3d67
linuxlinux>= 2e07e8348ea454615e268222ae3fc240421be768 < 817e8138ce86001b2fa5c63d6ede756e205a01f7817e8138ce86001b2fa5c63d6ede756e205a01f7
linuxlinux>= 2e07e8348ea454615e268222ae3fc240421be768 < 2c9e2df022ef8b9d7fac58a04a2ef4ed252889552c9e2df022ef8b9d7fac58a04a2ef4ed25288955
linuxlinux>= 2e07e8348ea454615e268222ae3fc240421be768 < f7b94bdc1ec107c92262716b073b3e816d4784fbf7b94bdc1ec107c92262716b073b3e816d4784fb
linuxlinux>= 5.10.206 < 5.115.11
linuxlinux>= 5.15.146 < 5.15.2095.15.209
linuxlinux>= 6.1.70 < 6.26.2
linuxlinux>= 6.6.9 < 6.6.236.6.23
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-117.1275.15.0-117.127
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 5.10.206 < 5.115.11
linuxlinux_kernel>= 5.15.146 < 5.165.16
linuxlinux_kernel>= 6.1.70 < 6.1.836.1.83
linuxlinux_kernel>= 6.6.9 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.