CVE-2026-53256
published 2026-06-25CVE-2026-53256: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()…
PriorityP341high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.27%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock,
but returns the selected listener after dropping that lock without
taking a reference. rfcomm_connect_ind() then locks the listener,
queues a child socket on it, and may notify it after unlocking it.
The buggy scenario involves two paths, with each column showing the
order within that path:
rfcomm_connect_ind(): listener close:
1. Find parent in 1. close() enters
rfcomm_get_sock_by_channel() rfcomm_sock_release().
2. Drop rfcomm_sk_list.lock 2. rfcomm_sock_shutdown()
without pinning parent. closes the listener.
3. Call lock_sock(parent) and 3. rfcomm_sock_kill()
bt_accept_enqueue(parent, unlinks and puts parent.
sk, true).
4. Read parent flags and may 4. parent can be freed.
call sk_state_change().
If close wins the race, parent can be freed before
rfcomm_connect_ind() reaches lock_sock(), bt_accept_enqueue(), or the
deferred-setup callback.
Take a reference on the listener before leaving rfcomm_sk_list.lock.
After lock_sock() succeeds, recheck that it is still in BT_LISTEN
before queueing a child, cache the deferred-setup bit while the parent
is locked, and drop the reference after the last parent use.
KASAN reported a slab-use-after-free in lock_sock_nested() from
rfcomm_connect_ind(), with the freeing stack going through
rfcomm_sock_kill() and rfcomm_sock_release().
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f5ec76bdbeb80f75ad0be204371afffee0f8fac8 | f5ec76bdbeb80f75ad0be204371afffee0f8fac8 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a07d741c077d4e34b16458241a94d29039386553 | a07d741c077d4e34b16458241a94d29039386553 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1f73f92f66251065a5f39b09a47cf05ea14d3107 | 1f73f92f66251065a5f39b09a47cf05ea14d3107 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < de31973ef00e5aa55496f84cf6a44bb157a34e02 | de31973ef00e5aa55496f84cf6a44bb157a34e02 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b0e33e409715c617e2a20f46f99aa5403a14dfda | b0e33e409715c617e2a20f46f99aa5403a14dfda |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8802413ce63175fb522a2bd609fb043a3550c720 | 8802413ce63175fb522a2bd609fb043a3550c720 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6f4462d12133106460d7c046b95aad2491e3fddf | 6f4462d12133106460d7c046b95aad2491e3fddf |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 43c441edacf953b39517a44f5e5e10a93618b226 | 43c441edacf953b39517a44f5e5e10a93618b226 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.12.1 < 5.10.259 | 5.10.259 |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list l
ghsa_unreviewed·2026-06-25
CVE-2026-53256 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list l
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock,
but returns the selected listener after dropping that lock without
taking a reference. rfcomm_connect_ind() then locks the listener,
queues a child socket on it, and may notify it after unlocking it.
The buggy scenario involves two paths, with each column showing the
order within that path:
rfcomm_connect_ind(): listener close:
1. Find parent in 1. close() enters
rfcomm_get_sock_by_channel() rfcomm_sock_release().
2. Drop rfcomm_sk_list.lock 2. rfcomm_sock_shutdown()
without pinning parent. closes the listener.
3. Call lock_sock(parent) and 3. rfcomm_sock_kill()
bt_accept_enqueue(parent
Red Hat
kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53256 [MEDIUM] CWE-364 kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
A flaw was found in the Linux kernel's Bluetooth RFCOMM (Radio Frequency Communication) subsystem. A race condition in the rfcomm_connect_ind() function, specifically during the handling of listener sockets, can lead to a use-after-free vulnerability. A local attacker could exploit this to cause a denial of service or potentially achieve arbitrary code execution.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1f73f92f66251065a5f39b09a47cf05ea14d3107https://git.kernel.org/stable/c/43c441edacf953b39517a44f5e5e10a93618b226https://git.kernel.org/stable/c/6f4462d12133106460d7c046b95aad2491e3fddfhttps://git.kernel.org/stable/c/8802413ce63175fb522a2bd609fb043a3550c720https://git.kernel.org/stable/c/a07d741c077d4e34b16458241a94d29039386553https://git.kernel.org/stable/c/b0e33e409715c617e2a20f46f99aa5403a14dfdahttps://git.kernel.org/stable/c/de31973ef00e5aa55496f84cf6a44bb157a34e02https://git.kernel.org/stable/c/f5ec76bdbeb80f75ad0be204371afffee0f8fac8
2026-06-25
Published