{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: RFCOMM: serialize security confirmation handling  rfcomm_security_cfm() looks up a session on session_list and then walks its DLC list without holding rfcomm_mutex. Since RFCOMM session teardown uses rfcomm_mutex, krfcommd can close and free the same session and DLCs concurrently:    hci_rx_work                    krfcommd   -----------                    ---------   rfcomm_session_get()                                  rfcomm_lock()                                  rfcomm_session_close()                                    rfcomm_dlc_unlink()                                    rfcomm_session_del()                                      kfree(s)                                  rfcomm_unlock()   walk s-\u003edlcs  The callback can then read a freed session list head and touch freed DLCs while updating their flags or timers.  Serialize the session lookup and DLC traversal in rfcomm_security_cfm() with rfcomm_mutex. This matches the existing RFCOMM session lifetime rules and prevents concurrent rfcomm_session_del() / rfcomm_dlc_unlink() from tearing the objects down while the callback is using them.  KASAN reported:    BUG: KASAN: slab-use-after-free in rfcomm_security_cfm+0x41c/0x440   Read of size 8 at addr ffff888111fb3960 by task kworker/u17:1/89   Workqueue: hci0 hci_rx_work   Call Trace:    rfcomm_security_cfm+0x41c/0x440    hci_encrypt_cfm+0x139/0x590    hci_encrypt_change_evt+0x37b/0xc40    hci_event_packet+0x71b/0xb20    hci_rx_work+0x293/0x730   Allocated by task 69:    rfcomm_session_add+0x9e/0x2f0    rfcomm_run+0x44b/0x41e0   Freed by task 69:    kfree+0x131/0x3c0    rfcomm_session_del+0x188/0x220    rfcomm_run+0x1985/0x41e0",
  "id": "DEBIAN-CVE-2026-89569",
  "modified": "2026-09-15T08:47:40.938788528Z",
  "published": "2026-09-11T20:19:40.920Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89569"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89569"
  ]
}