CVE-2026-52918
published 2026-06-24CVE-2026-52918: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without…
PriorityP344high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.27%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: serialize accept_q access
bt_sock_poll() walks the accept queue without synchronization, while
child teardown can unlink the same socket and drop its last reference.
The unsynchronized accept queue walk has existed since the initial
Bluetooth import.
Protect accept_q with a dedicated lock for queue updates and polling.
Also rework bt_accept_dequeue() to take temporary child references under
the queue lock before dropping it and locking the child socket.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d9ce4de05df2385c19e2c7d12f529144e1a44af1 | d9ce4de05df2385c19e2c7d12f529144e1a44af1 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 41c8c1c7923e86e0eb59cfb4279349112756a336 | 41c8c1c7923e86e0eb59cfb4279349112756a336 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4ec17782fd186f901a7329605d11048b085b945a | 4ec17782fd186f901a7329605d11048b085b945a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < be43e6b4043113c3b3cf887c3c8350f67140274c | be43e6b4043113c3b3cf887c3c8350f67140274c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 85f8674cae82053f1e6bab295f6a8422cca14db5 | 85f8674cae82053f1e6bab295f6a8422cca14db5 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8b4c412e001b0c670eb937beab491af974da55b3 | 8b4c412e001b0c670eb937beab491af974da55b3 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a218bf69eb51fefe59a3976fa8925261141f681c | a218bf69eb51fefe59a3976fa8925261141f681c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e83f5e24da741fa9405aeeff00b08c5ee7c37b88 | e83f5e24da741fa9405aeeff00b08c5ee7c37b88 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.12.1 < 5.10.259 | 5.10.259 |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.34 | 6.18.34 |
| linux | linux_kernel | >= 6.19 < 7.0.11 | 7.0.11 |
| linux | linux_kernel | >= 6.2 < 6.6.142 | 6.6.142 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, while child teardown can unlin
ghsa_unreviewed·2026-06-24
CVE-2026-52918 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, while child teardown can unlin
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: serialize accept_q access
bt_sock_poll() walks the accept queue without synchronization, while
child teardown can unlink the same socket and drop its last reference.
The unsynchronized accept queue walk has existed since the initial
Bluetooth import.
Protect accept_q with a dedicated lock for queue updates and polling.
Also rework bt_accept_dequeue() to take temporary child references under
the queue lock before dropping it and locking the child socket.
Red Hat
kernel: Bluetooth: serialize accept_q access
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-52918 [MEDIUM] CWE-820 kernel: Bluetooth: serialize accept_q access
kernel: Bluetooth: serialize accept_q access
A flaw was found in the Linux kernel's Bluetooth subsystem. A race condition exists in the handling of the `accept_q` within the `bt_sock_poll()` function due to a lack of synchronization. This could allow a local attacker to cause a denial of service by manipulating socket operations during child teardown, leading to system instability.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Affec
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/41c8c1c7923e86e0eb59cfb4279349112756a336https://git.kernel.org/stable/c/4ec17782fd186f901a7329605d11048b085b945ahttps://git.kernel.org/stable/c/85f8674cae82053f1e6bab295f6a8422cca14db5https://git.kernel.org/stable/c/8b4c412e001b0c670eb937beab491af974da55b3https://git.kernel.org/stable/c/a218bf69eb51fefe59a3976fa8925261141f681chttps://git.kernel.org/stable/c/be43e6b4043113c3b3cf887c3c8350f67140274chttps://git.kernel.org/stable/c/d9ce4de05df2385c19e2c7d12f529144e1a44af1https://git.kernel.org/stable/c/e83f5e24da741fa9405aeeff00b08c5ee7c37b88
2026-06-24
Published