Updated: 2026-01-16 03:26:18.581978
Description:
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap_chan_destroy(struct kref *kref) Bluetooth: chan 0000000023c4974d Bluetooth: parent 00000000ae861c08 ================================================================== BUG: KASAN: use-after-free in __mutex_waiter_is_first kernel/locking/mutex.c:191 [inline] BUG: KASAN: use-after-free in __mutex_lock_common kernel/locking/mutex.c:671 [inline] BUG: KASAN: use-after-free in __mutex_lock+0x278/0x400 kernel/locking/mutex.c:729 Read of size 8 at addr ffff888006a49b08 by task kworker/u3:2/389
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | HIGH | 8.0 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 6 ELS | kernel | 2.6.32 | 8.0 | HIGH | Not Vulnerable | 2026-01-08 16:47:56 | ||
| CentOS 7 ELS | kernel | 3.10.0 | 8.0 | HIGH | Released | CLSA-2025:1766617167 | 2026-01-12 18:19:49 | |
| CentOS 8.4 ELS | kernel | 4.18.0 | 8.0 | HIGH | Needs Triage | 2025-10-28 09:07:44 | ||
| CentOS 8.5 ELS | kernel | 4.18.0 | 8.0 | HIGH | Needs Triage | 2026-01-16 17:28:17 | ||
| CentOS Stream 8 ELS | kernel | 4.18.0 | 8.0 | HIGH | Released | CLSA-2025:1763722365 | 2026-01-26 23:32:32 | |
| CloudLinux 7 ELS | kernel | 3.10.0 | 8.0 | HIGH | Ignored | 2025-12-27 04:51:11 | CloudLinux 6 and 7 support is limited and provided on demand. We strongly recommend upgrading to Clo... | |
| Oracle Linux 6 ELS | kernel | 2.6.32 | 8.0 | HIGH | Needs Triage | 2025-12-14 08:40:21 | ||
| Oracle Linux 7 ELS | kernel | 3.10.0 | 8.0 | HIGH | Released | CLSA-2025:1766599987 | 2025-12-25 14:41:46 | |
| Oracle Linux 7 ELS | kernel-uek | 5.4.17 | 8.0 | HIGH | Already Fixed | 2026-02-03 16:21:13 | ||
| RHEL 7 ELS | kernel | 3.10.0 | 8.0 | HIGH | Released | CLSA-2025:1766600619 | 2025-12-25 14:41:44 |