cbcvebase.
CVE-2026-53071
published 2026-06-24

CVE-2026-53071: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp()…

PriorityP346high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.27%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().

Affected

10 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 96dca51715d86559ed6ed8028e5445cecb80f3ae96dca51715d86559ed6ed8028e5445cecb80f3ae
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 330b20ec97916961ee0e6c29c06bc0fa7c96e64c330b20ec97916961ee0e6c29c06bc0fa7c96e64c
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 0ccd75c51f620374086f359e906917676e699a1c0ccd75c51f620374086f359e906917676e699a1c
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 77a853aec710b2fdf41fa298ea3cbc9a4358f91777a853aec710b2fdf41fa298ea3cbc9a4358f917
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < fe1188abdae9b7a8199dcdfcf9244d5e5d61eb14fe1188abdae9b7a8199dcdfcf9244d5e5d61eb14
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < dc89961b76f12aff47124c1df4bdb32a080f4d0cdc89961b76f12aff47124c1df4bdb32a080f4d0c
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 5501d055a1ce3c747141e3955ba8cf034d193f3e5501d055a1ce3c747141e3955ba8cf034d193f3e
linuxlinux>= 15f02b91056253e8cdc592888f431da0731337b8 < 42776497cdbc9a665b384a6dcb85f0d4bd927eab42776497cdbc9a665b384a6dcb85f0d4bd927eab
linuxlinux_kernel

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.