CVE-2026-53358 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile