Answer in brief
CVE-2026-90093 records a Unknown severity vulnerability in Bluetooth: L2CAP: access chan->conn safely in get/setsockopt. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b66774b48dd98f07254951f74ea6f513efe7ff8b <f49321c85785178214fd67f2e9b4b73d6363783b || >=b66774b48dd98f07254951f74ea6f513efe7ff8b <ca2c4c26498643f421d35ffe258fafbd3ed461c3 || 8f90405a4a6f1f1880dc07996b47bf57c712bd8a || 32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b || 8922c7940bae9ce4b1736dddb6362370793835c2 || 91047a4396a8b1857a6f712a90cf33ec0012b189 || 0b0e2bf39cf99e458d991b9df253727e036a7d7d || d3b739db5dc6f688a60d56da872fabaf65246032 || 50c38d9f42a529691e4e67ea9cedf4f0bfc8d277 || >=5.10.265 <5.11 || >=5.15.216 <5.16 || >=6.1.183 <6.2 || >=6.6.145 <6.7 || >=6.12.97 <6.13 || >=6.18.39 <6.19 || >=7.1.4 <7.2 | f49321c85785178214fd67f2e9b4b73d6363783b, ca2c4c26498643f421d35ffe258fafbd3ed461c3, 5.11, 5.16, 6.2, 6.7, 6.13, 6.19, 7.2 |
| Linux/Linuxgeneric | 7.2 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in l2cap_sock_setsockopt() access of conn->hcon->hdev. Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in getsockopt/setsockopt to ensure it stays alive, and to avoid data races in l2cap_chan fields.
Quoted source text, attributed separately from HOL analysis.