Linux Kernel Bluetooth Circular Lock Vulnerability in ISO Connection Synchronization

Vulnerability

A vulnerability in the Linux kernel's Bluetooth implementation has been addressed, specifically related to circular locking dependencies in ISO connection synchronization. The issue arose because the socket lock was not released before calling a function that required locking the hardware device lock, leading to potential deadlocks. This vulnerability was present in Linux kernel versions through 6.12.0-rc6.

Impact

Exploitation of this vulnerability could lead to a deadlock situation, where two tasks are unable to proceed because each is waiting for the other to release a lock, potentially causing system hangs or unresponsiveness.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.