{"id":"CVE-2024-26886","summary":"Bluetooth: af_bluetooth: Fix deadlock","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: af_bluetooth: Fix deadlock\n\nAttemting to do sock_lock on .recvmsg may cause a deadlock as shown\nbellow, so instead of using sock_sock this uses sk_receive_queue.lock\non bt_sock_ioctl to avoid the UAF:\n\nINFO: task kworker/u9:1:121 blocked for more than 30 seconds.\n      Not tainted 6.7.6-lemon #183\nWorkqueue: hci0 hci_rx_work\nCall Trace:\n \u003cTASK\u003e\n __schedule+0x37d/0xa00\n schedule+0x32/0xe0\n __lock_sock+0x68/0xa0\n ? __pfx_autoremove_wake_function+0x10/0x10\n lock_sock_nested+0x43/0x50\n l2cap_sock_recv_cb+0x21/0xa0\n l2cap_recv_frame+0x55b/0x30a0\n ? psi_task_switch+0xeb/0x270\n ? finish_task_switch.isra.0+0x93/0x2a0\n hci_rx_work+0x33a/0x3f0\n process_one_work+0x13a/0x2f0\n worker_thread+0x2f0/0x410\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe0/0x110\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2c/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \u003c/TASK\u003e","modified":"2026-04-02T10:06:18.563216Z","published":"2024-04-17T10:27:40.941Z","related":["ALSA-2024:6567","SUSE-SU-2024:4367-1","SUSE-SU-2025:0035-1","SUSE-SU-2025:0201-1","SUSE-SU-2025:0201-2","SUSE-SU-2025:0229-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26886.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2c9e2df022ef8b9d7fac58a04a2ef4ed25288955"},{"type":"WEB","url":"https://git.kernel.org/stable/c/64be3c6154886200708da0dfe259705fb992416c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/817e8138ce86001b2fa5c63d6ede756e205a01f7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cb8adca52f306563d958a863bb0cbae9c184d1ae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f7b94bdc1ec107c92262716b073b3e816d4784fb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26886.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26886"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"1d576c3a5af850bf11fbd103f9ba11aa6d6061fb"},{"fixed":"64be3c6154886200708da0dfe259705fb992416c"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"2e07e8348ea454615e268222ae3fc240421be768"},{"fixed":"817e8138ce86001b2fa5c63d6ede756e205a01f7"},{"fixed":"2c9e2df022ef8b9d7fac58a04a2ef4ed25288955"},{"fixed":"f7b94bdc1ec107c92262716b073b3e816d4784fb"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"0"},{"last_affected":"db1b14eec8c61a20374de9f9c2ddc6c9406a8c42"},{"last_affected":"2b16d960c79abc397f102c3d23d30005b68cb036"},{"last_affected":"37f71e2c9f515834841826f4eb68ec33cfb2a1ff"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26886.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}