{"id":"AZL-106152","summary":"CVE-2026-98290 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which takes the child socket lock before\nrfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these\nlocks in reverse order while handling connections and DLC state changes,\nso lockdep reports a possible deadlock.\n\nClose dequeued children without taking their socket lock. The accept queue\nowns a reference to each child, and bt_accept_dequeue() locks the child\nwhile unlinking it and clearing its parent pointer.\n\nDropping the child lock makes it important to prevent a concurrent\nrfcomm_connect_ind() from enqueueing a new child after cleanup observes an\nempty queue. Set a listening socket to BT_CLOSED while its lock is still\nheld, before dropping the lock and draining the queue. The state check in\nrfcomm_connect_ind() then rejects new children once cleanup starts.","modified":"2026-10-07T14:16:56.117218755Z","published":"2026-10-06T09:18:19Z","upstream":["CVE-2026-98290"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98290"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106152.json"}}],"schema_version":"1.9.0"}