Answer in brief
CVE-2026-98290 records a Unknown severity vulnerability in Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b7ce436a5d798bc59e71797952566608a4b4626b <eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c || >=b7ce436a5d798bc59e71797952566608a4b4626b <4aafb47301a799d3e01230d6568c4e93524e1523 || >=b7ce436a5d798bc59e71797952566608a4b4626b <c741977e413f5b49d306700820fb55ccb8269f5a || >=b7ce436a5d798bc59e71797952566608a4b4626b <c6792c441767256030606eb82dca5d5fc360dd9a || >=b7ce436a5d798bc59e71797952566608a4b4626b <bfce253f039eb5f58b810af267942a9f59207254 || >=b7ce436a5d798bc59e71797952566608a4b4626b <18174b166547ef41973cc19feb5ef9cab39a8def || >=b7ce436a5d798bc59e71797952566608a4b4626b <801fb950cae7048eb7d83b18857d1ca37b8cd5a4 | eb4adaa46e4c9e6efa7be3ce06398f4d7c39b57c, 4aafb47301a799d3e01230d6568c4e93524e1523, c741977e413f5b49d306700820fb55ccb8269f5a, c6792c441767256030606eb82dca5d5fc360dd9a, bfce253f039eb5f58b810af267942a9f59207254, 18174b166547ef41973cc19feb5ef9cab39a8def, 801fb950cae7048eb7d83b18857d1ca37b8cd5a4 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock. Close dequeued children without taking their socket lock. The accept queue owns a reference to each child, and bt_accept_dequeue() locks the child while unlinking it and clearing its parent pointer. Dropping the child lock makes it important to prevent a concurrent rfcomm_connect_ind() from enqueueing a new child after cleanup observes an empty queue. Set a listening socket to BT_CLOSED while its lock is still held, before dropping the lock and draining the queue. The state check in rfcomm_connect_ind() then rejects new children once cleanup starts.
Quoted source text, attributed separately from HOL analysis.