<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:54:28 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-47038 — Bluetooth: avoid deadlock between hci_dev-&gt;lock and socket lock</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-47038</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: avoid deadlock between hci_dev-&amp;gt;lock and socket lock&lt;/p&gt;
&lt;p&gt;Commit eab2404ba798 (&amp;#34;Bluetooth: Add BT_PHY socket option&amp;#34;) added a
dependency between socket lock and hci_dev-&amp;gt;lock that could lead to
deadlock.&lt;/p&gt;
&lt;p&gt;It turns out that hci_conn_get_phy() is not in any way relying on hdev
being immutable during the runtime of this function, neither does it even
look at any of the members of hdev, and as such there is no need to hold
that lock.&lt;/p&gt;
&lt;p&gt;This fixes the lockdep splat below:&lt;/p&gt;
&lt;p&gt;======================================================
 WARNING: possible circular locking dependency detected
 5.12.0-rc1-00026-g73d464503354 #10 Not tainted
 ------------------------------------------------------
 bluetoothd/1118 is trying to acquire lock:
 ffff8f078383c078 (&amp;amp;hdev-&amp;gt;lock){+.+.}-{3:3}, at: hci_conn_get_phy+0x1c/0x150 [bluetooth]&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}, at: l2cap_sock_getsockopt+0x8b/0x610&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #3 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}:
        lock_sock_nested+0x72/0xa0
        l2cap_sock_ready_cb+0x18/0x70 [bluetooth]
        l2cap_config_rsp+0x27a/0x520 [bluetooth]
        l2cap_sig_channel+0x658/0x1330 [bluetooth]
        l2cap_recv_frame+0x1ba/0x310 [bluetooth]
        hci_rx_work+0x1cc/0x640 [bluetooth]
        process_one_work…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: avoid deadlock between hci_dev-&amp;gt;lock and socket lock&lt;/p&gt;
&lt;p&gt;Commit eab2404ba798 (&amp;#34;Bluetooth: Add BT_PHY socket option&amp;#34;) added a
dependency between socket lock and hci_dev-&amp;gt;lock that could lead to
deadlock.&lt;/p&gt;
&lt;p&gt;It turns out that hci_conn_get_phy() is not in any way relying on hdev
being immutable during the runtime of this function, neither does it even
look at any of the members of hdev, and as such there is no need to hold
that lock.&lt;/p&gt;
&lt;p&gt;This fixes the lockdep splat below:&lt;/p&gt;
&lt;p&gt;======================================================
 WARNING: possible circular locking dependency detected
 5.12.0-rc1-00026-g73d464503354 #10 Not tainted
 ------------------------------------------------------
 bluetoothd/1118 is trying to acquire lock:
 ffff8f078383c078 (&amp;amp;hdev-&amp;gt;lock){+.+.}-{3:3}, at: hci_conn_get_phy+0x1c/0x150 [bluetooth]&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}, at: l2cap_sock_getsockopt+0x8b/0x610&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #3 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}:
        lock_sock_nested+0x72/0xa0
        l2cap_sock_ready_cb+0x18/0x70 [bluetooth]
        l2cap_config_rsp+0x27a/0x520 [bluetooth]
        l2cap_sig_channel+0x658/0x1330 [bluetooth]
        l2cap_recv_frame+0x1ba/0x310 [bluetooth]
        hci_rx_work+0x1cc/0x640 [bluetooth]
        process_one_work…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-47038</guid>
    </item>
  </channel>
</rss>
