CVE-2026-68393
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: extend conn_hash lookup critical sections
Using RCU-protected pointers outside the critical sections without refcount is incorrect and may result to UAF.
Extend critical section to cover both hci_conn_hash lookup and use of the returned conn.
Add surrounding rcu_read_lock() also when return value is not used, in preparation for RCU lockdep requirement to hci_lookup_le_connect().
This avoids concurrent deletion of the conn before we are done dereferencing it.
Also, make sure to hold hdev->lock when accessing hdev->accept_list.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6d0417e4e1cf66fd917f06f0454958362714ef7d < 83b7e67698d0b93f685875ce82c8d335436834f7 | affected |
| Linux | Linux | 6d0417e4e1cf66fd917f06f0454958362714ef7d < 38326774df6198df0cc2744cc73bf77cb741c538 | affected |
| Linux | Linux | 6d0417e4e1cf66fd917f06f0454958362714ef7d < d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d | affected |
| Linux | Linux | eb8b860e87b296bd1874c79a668081efd00f9754 | affected |
| Linux | Linux | 94bf6380e936339a700c0b3171a49baf512aa70b | affected |
| Linux | Linux | 6.12.28 < 6.13 | affected |
| Linux | Linux | 6.14.6 < 6.15 | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/83b7e67698d0b93f685875ce82c8d335436834f7
- https://git.kernel.org/stable/c/38326774df6198df0cc2744cc73bf77cb741c538
- https://git.kernel.org/stable/c/d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.