CVE-2026-74529
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
There is theoretical UAF if the conn is freed while the hci_sync task is running.
Hold refcount to avoid that.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6d0417e4e1cf66fd917f06f0454958362714ef7d < c53c70ec289ee12f20c4f1b2fbfd151762c01f67 | affected |
| Linux | Linux | 6d0417e4e1cf66fd917f06f0454958362714ef7d < 44fc74069d8988f2825246f9401218e29de2c0ab | affected |
| Linux | Linux | eb8b860e87b296bd1874c79a668081efd00f9754 | affected |
| Linux | Linux | 94bf6380e936339a700c0b3171a49baf512aa70b | affected |
| Linux | Linux | 6.12.28 < 6.13 | affected |
| Linux | Linux | 6.14.6 < 6.15 | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 7.1.8 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc6 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c53c70ec289ee12f20c4f1b2fbfd151762c01f67
- https://git.kernel.org/stable/c/44fc74069d8988f2825246f9401218e29de2c0ab
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.