CVE-2026-98297 (GCVE-0-2026-98297)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-06 08:45
VLAI
Title
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work unconditionally. They can run from the L2CAP/SCO/ISO socket send path while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN racing with a socket write). Since that queue_work() is not chained work from the tx_work worker itself, __queue_work() sees the queue marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops the work: WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work Call Trace: queue_work_on l2cap_chan_send l2cap_sock_sendmsg ... hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer() check it before queuing. Route the tx_work producers through the same guard via a shared hci_sched_tx() helper.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9 , < ab0678a0701ac4de499428dc1b321659bb74d272 (git)
Affected: 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e , < e220c1242a643d97102a79f09b7ef3aa31276961 (git)
Affected: 525daaea459fc215f432de1b8debbd9144bf97b0 , < cbb325bc150e8c0dbce004ac0e5516bcffc0de31 (git)
Affected: 525daaea459fc215f432de1b8debbd9144bf97b0 , < 6610c6fe4b8936c232048e6049bf77c70a6f759c (git)
Affected: 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff (git)
Affected: 6.12.93 , < 6.12.112 (semver)
Affected: 6.18.35 , < 6.18.54 (semver)
Affected: 7.0.12 , < 7.1 (semver)
Create a notification for this product.
Linux Linux Affected: 7.1
Unaffected: 0 , < 7.1 (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ab0678a0701ac4de499428dc1b321659bb74d272",
              "status": "affected",
              "version": "9cebe4680bb9a72f80c6541eb24af06db7a1fbc9",
              "versionType": "git"
            },
            {
              "lessThan": "e220c1242a643d97102a79f09b7ef3aa31276961",
              "status": "affected",
              "version": "47330cc875b36a1cf7b3543cb2cf90a7c603ce0e",
              "versionType": "git"
            },
            {
              "lessThan": "cbb325bc150e8c0dbce004ac0e5516bcffc0de31",
              "status": "affected",
              "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
              "versionType": "git"
            },
            {
              "lessThan": "6610c6fe4b8936c232048e6049bf77c70a6f759c",
              "status": "affected",
              "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff",
              "versionType": "git"
            },
            {
              "lessThan": "6.12.112",
              "status": "affected",
              "version": "6.12.93",
              "versionType": "semver"
            },
            {
              "lessThan": "6.18.54",
              "status": "affected",
              "version": "6.18.35",
              "versionType": "semver"
            },
            {
              "lessThan": "7.1",
              "status": "affected",
              "version": "7.0.12",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "lessThan": "7.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "6.12.93",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "6.18.35",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "7.0.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix queuing tx_work after workqueue is drained\n\nhci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev-\u003etx_work\nunconditionally. They can run from the L2CAP/SCO/ISO socket send path\nwhile hci_dev_close_sync() is draining hdev-\u003eworkqueue (HCIDEVDOWN\nracing with a socket write). Since that queue_work() is not chained\nwork from the tx_work worker itself, __queue_work() sees the queue\nmarked __WQ_DRAINING, warns \"cannot queue %ps on wq %s\", and drops\nthe work:\n\n  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work\n  Call Trace:\n   queue_work_on\n   l2cap_chan_send\n   l2cap_sock_sendmsg\n   ...\n\nhci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before\ndraining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()\ncheck it before queuing. Route the tx_work producers through the\nsame guard via a shared hci_sched_tx() helper."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:45:55.723Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ab0678a0701ac4de499428dc1b321659bb74d272"
        },
        {
          "url": "https://git.kernel.org/stable/c/e220c1242a643d97102a79f09b7ef3aa31276961"
        },
        {
          "url": "https://git.kernel.org/stable/c/cbb325bc150e8c0dbce004ac0e5516bcffc0de31"
        },
        {
          "url": "https://git.kernel.org/stable/c/6610c6fe4b8936c232048e6049bf77c70a6f759c"
        }
      ],
      "title": "Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98297",
    "datePublished": "2026-10-06T08:45:55.723Z",
    "dateReserved": "2026-09-25T10:25:14.337Z",
    "dateUpdated": "2026-10-06T08:45:55.723Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98297",
      "date": "2026-10-09",
      "epss": "0.00175",
      "percentile": "0.06434"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/bluetooth/hci_core.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "ab0678a0701ac4de499428dc1b321659bb74d272",
                    "status": "affected",
                    "version": "9cebe4680bb9a72f80c6541eb24af06db7a1fbc9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e220c1242a643d97102a79f09b7ef3aa31276961",
                    "status": "affected",
                    "version": "47330cc875b36a1cf7b3543cb2cf90a7c603ce0e",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "cbb325bc150e8c0dbce004ac0e5516bcffc0de31",
                    "status": "affected",
                    "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6610c6fe4b8936c232048e6049bf77c70a6f759c",
                    "status": "affected",
                    "version": "525daaea459fc215f432de1b8debbd9144bf97b0",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6.12.112",
                    "status": "affected",
                    "version": "6.12.93",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.18.54",
                    "status": "affected",
                    "version": "6.18.35",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "7.1",
                    "status": "affected",
                    "version": "7.0.12",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/bluetooth/hci_core.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "lessThan": "7.1",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix queuing tx_work after workqueue is drained\n\nhci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev-\u003etx_work\nunconditionally. They can run from the L2CAP/SCO/ISO socket send path\nwhile hci_dev_close_sync() is draining hdev-\u003eworkqueue (HCIDEVDOWN\nracing with a socket write). Since that queue_work() is not chained\nwork from the tx_work worker itself, __queue_work() sees the queue\nmarked __WQ_DRAINING, warns \"cannot queue %ps on wq %s\", and drops\nthe work:\n\n  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work\n  Call Trace:\n   queue_work_on\n   l2cap_chan_send\n   l2cap_sock_sendmsg\n   ...\n\nhci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before\ndraining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()\ncheck it before queuing. Route the tx_work producers through the\nsame guard via a shared hci_sched_tx() helper."
          }
        ],
        "id": "CVE-2026-98297",
        "lastModified": "2026-10-06T09:18:20.400",
        "metrics": {},
        "published": "2026-10-06T09:18:20.400",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/6610c6fe4b8936c232048e6049bf77c70a6f759c"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ab0678a0701ac4de499428dc1b321659bb74d272"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/cbb325bc150e8c0dbce004ac0e5516bcffc0de31"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e220c1242a643d97102a79f09b7ef3aa31276961"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "low",
      "current_release_date": "2026-10-08T16:48:22Z",
      "cve": "CVE-2026-98297",
      "id": "CVE-2026-98297",
      "initial_release_date": "2026-10-08T16:48:22Z",
      "product_status:known_not_affected": "347",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98297",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98297.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…