cbcvebase.
CVE-2026-53358
published 2026-07-02

CVE-2026-53358: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close()…

PriorityP343high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously. The timeout handler already acquires conn->lock and chan->lock in the correct order. The timer is only armed when chan->conn is still set: if it is already NULL, l2cap_conn_del() has already processed this channel (l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb), so there is nothing left to do. If l2cap_conn_del() races in after the timer is armed, __clear_chan_timer() inside l2cap_chan_del() cancels it; if the timer has already fired, the handler returns harmlessly because chan->conn was cleared.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 3634cbdc2eb414b69ffa752ddbe5e0458518e3213634cbdc2eb414b69ffa752ddbe5e0458518e321
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < e1c100e2d61bd8c718b7d91fe3e050780a9bf72de1c100e2d61bd8c718b7d91fe3e050780a9bf72d
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 89dec92041717b027216e110599e4f6d6c921b7989dec92041717b027216e110599e4f6d6c921b79
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 50dfec218808b148ab4247b1858031b7a32015c550dfec218808b148ab4247b1858031b7a32015c5
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 859d3ace791ed878ae9ba5522c7844d960da8f88859d3ace791ed878ae9ba5522c7844d960da8f88
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 7555fd885a0603f50e49a655850a1f2bd8a253987555fd885a0603f50e49a655850a1f2bd8a25398
linuxlinux>= 3df91ea20e744344100b10ae69a17211fcf5b207 < 8c8e620467a7b51562dbcefbd1f09f288d7d710d8c8e620467a7b51562dbcefbd1f09f288d7d710d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 3.4 < 5.10.2595.10.259
linuxlinux_kernel>= 5.11 < 5.15.2105.15.210
linuxlinux_kernel>= 5.16 < 6.1.1766.1.176
linuxlinux_kernel>= 6.13 < 6.18.356.18.35
linuxlinux_kernel>= 6.19 < 7.0.127.0.12
linuxlinux_kernel>= 6.2 < 6.6.1436.6.143
linuxlinux_kernel>= 6.7 < 6.12.936.12.93
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.0HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.