CVE-2026-68393

Summary

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: extend conn_hash lookup critical sections

Using RCU-protected pointers outside the critical sections without refcount is incorrect and may result to UAF.

Extend critical section to cover both hci_conn_hash lookup and use of the returned conn.

Add surrounding rcu_read_lock() also when return value is not used, in preparation for RCU lockdep requirement to hci_lookup_le_connect().

This avoids concurrent deletion of the conn before we are done dereferencing it.

Also, make sure to hold hdev->lock when accessing hdev->accept_list.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux6d0417e4e1cf66fd917f06f0454958362714ef7d < 83b7e67698d0b93f685875ce82c8d335436834f7affected
LinuxLinux6d0417e4e1cf66fd917f06f0454958362714ef7d < 38326774df6198df0cc2744cc73bf77cb741c538affected
LinuxLinux6d0417e4e1cf66fd917f06f0454958362714ef7d < d5efd6e4b8b0634af6843178fe1a7dd2b2178a3daffected
LinuxLinuxeb8b860e87b296bd1874c79a668081efd00f9754affected
LinuxLinux94bf6380e936339a700c0b3171a49baf512aa70baffected
LinuxLinux6.12.28 < 6.13affected
LinuxLinux6.14.6 < 6.15affected
LinuxLinux6.15affected
LinuxLinux0 < 6.15unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc4 <= *unaffected

Weaknesses

References