Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026062404-CVE-2026-53071-bdae@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:42550 https://access.redhat.com/errata/RHSA-2026:42550
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:42552 https://access.redhat.com/errata/RHSA-2026:42552
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:42919 https://access.redhat.com/errata/RHSA-2026:42919
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:43307 https://access.redhat.com/errata/RHSA-2026:43307
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:65710 https://access.redhat.com/errata/RHSA-2026:65710
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:65711 https://access.redhat.com/errata/RHSA-2026:65711