CVE-2026-90093: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has held reference and remains non-NULL also after the corresponding hci_conn is deleted. In this state accessing various fields eg. hci_conn::hdev is invalid, which leads to KASAN crash in l2cap_sock_setsockopt() access of conn->hcon->hdev. Check l2cap_chan::conn.hcon corresponds to an alive hci_conn before trying to use it in l2cap_sock.c. Hold l2cap_chan_lock() in getsockopt/setsockopt to ensure it stays alive, and to avoid data races in l2cap_chan fields.
Affected products
- Linux Linux: from 5.10.265, before 5.11 (fixed in 5.11); from 5.15.216, before 5.16 (fixed in 5.16); from 6.1.183, before 6.2 (fixed in 6.2); from 6.6.145, before 6.7 (fixed in 6.7); from 6.12.97, before 6.13 (fixed in 6.13); from 6.18.39, before 6.19 (fixed in 6.19); …
Published 2026-09-17. Last modified 2026-09-18.