High [CVE-2026-68188] Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios
This high-severity Red Hat Linux advisory covers CVE-2026-68188 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initiator and session->sock.
Meanwhile, krfcommd can unlink the DLC and free the session while holding rfcomm_mutex. Have the TTY path use the helper and drop its unlocked session check.
This keeps the session valid through both the frame construction and socket send. A race condition in the `rfcomm_tty_set_termios()` function allows a session to be freed while it is still actively in use.
This use-after-free (UAF) vulnerability can be exploited by a local attacker. Successful exploitation leads to a system crash, resulting in a Denial of Service (DoS).
Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-364.
Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 8.
Red Hat does not currently list a fixing RHSA for this CVE.
Affected products named by the advisory: Red Hat package: kernel-rt.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 30 days ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 30 days ago·verify at source
Mitigation checklist
- To prevent the `rfcomm` kernel module from loading, create a modprobe configuration file. Add the following lines to `/etc/modprobe.d/disable-rfcomm.conf`: ``` install rfcomm /bin/true blacklist rfcomm ``` After saving the file, regenerate the initramfs and reboot the system for the changes to take effect. This action will disable Bluetooth RFCOMM functionality. If the module is currently loaded, unload it with `rmmod rfcomm`; however, a system reboot is recommended to ensure the module is not loaded.
Official advisory · high-confidence parse· fetched 30 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.