Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63948— Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于Bluetooth L2CAP中l2cap_chan_timeout()函数在chan->conn为NULL时未释放引用,导致引用泄漏。

AI Predicted 3.3 Difficulty: Trivial EPSS 0.22% · P12

Possible ATT&CK Techniques 1 AI

T1562

Affected Version Matrix 28

VendorProduct Version RangeStatus
Linux Linux 06acb75e7ed600d0bbf7bff5628aa8f24a97978c< 50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee affected
e97e16433eb4533083b096a3824b93a5ca3aee79< b5c59a5b469e2a809a2d57eda4ded94235971060 affected
8960ff650aec70485b40771cd8e6e8c4cb467d33< 8894c2010435a56ce7c6c2a8785860c13554df2f affected
955b5b6c54d95b5e7444dfc81c95c8e013f27ac0< 63cd225cc13d782a85e2a73c04d0d350153eada1 affected
adf0398cee86643b8eacde95f17d073d022f782c< 107c826e4ef9ec5ad8f60e6fe64d8d5325ba508f affected
adf0398cee86643b8eacde95f17d073d022f782c< e8a5baff5be273ca07771fd2b9bb1f2a4152917b affected
adf0398cee86643b8eacde95f17d073d022f782c< 08d81fe96f80a8e20c7acb573b6a45d901fcf2cd affected
adf0398cee86643b8eacde95f17d073d022f782c< 9dbd84990394c51f5cee1e8871bb5ff8af5ed939 affected
… +20 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63948

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn __set_chan_timer() takes a l2cap_chan reference via l2cap_chan_hold() before scheduling the delayed work. The normal path in l2cap_chan_timeout() drops this reference with l2cap_chan_put() at the end, but the early return when chan->conn is NULL skips the put, leaking the reference. Add the missing l2cap_chan_put() before the early return.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于Bluetooth L2CAP中l2cap_chan_timeout()函数在chan->conn为NULL时未释放引用,导致引用泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 06acb75e7ed600d0bbf7bff5628aa8f24a97978c ~ 50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee -
Linux Linux 6.9 -

II. Public POCs for CVE-2026-63948

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63948

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63948 (7)

Same Patch Batch · Linux · 2026-07-19 · 429 CVEs total

CVE-2026-63795 10.0 CRITICAL 9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-64037 9.8 CRITICAL wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
CVE-2026-63993 9.8 CRITICAL vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
CVE-2026-63994 9.8 CRITICAL tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-64142 9.8 CRITICAL ksmbd: close durable scavenger races against m_fp_list lookups
CVE-2026-64000 9.8 CRITICAL net: hsr: fix potential OOB access in supervision frame handling
CVE-2026-64046 9.8 CRITICAL net: tls: prevent chain-after-chain in plain text SG
CVE-2026-64162 9.8 CRITICAL idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
CVE-2026-53399 9.8 CRITICAL nfsd: release layout stid on setlease failure
CVE-2026-53398 9.8 CRITICAL NFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-64007 9.8 CRITICAL netfilter: synproxy: refresh tcphdr after skb_ensure_writable
CVE-2026-63825 9.8 CRITICAL gcov: use atomic counter updates to fix concurrent access crashes
CVE-2026-64016 9.8 CRITICAL ksmbd: fix durable reconnect error path file lifetime
CVE-2026-63800 9.8 CRITICAL pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63808 9.8 CRITICAL exfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-64025 9.8 CRITICAL bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
CVE-2026-64125 9.8 CRITICAL net: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-64033 9.8 CRITICAL RDMA/rtrs: Fix use-after-free in path file creation cleanup
CVE-2026-64089 9.8 CRITICAL batman-adv: tt: fix negative last_changeset_len
CVE-2026-64035 9.8 CRITICAL igc: set tx buffer type for SMD frames

Showing top 20 of 429 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-63948

No comments yet


Leave a comment