DEBIAN-CVE-2026-53071

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 24 Jun 2026, 17:17
Last modified:05 Jul 2026, 20:01

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Jun 2026, 17:17
Published
Vulnerability first disclosed
05 Jul 2026, 20:01
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • debianlinux

    all | all | < 5.10.259-1 | < 6.1.176-1 | < 6.12.94-1 | < 7.0.10-1

  • debianlinux-6.1

    < 6.1.176-1~deb11u1

References (1)