CVE-2026-80692

Summary

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks

There is theoretical UAF if the conn is freed while the hci_sync task is running.

Hold refcount to avoid that.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux881559af5f5c545f6828e7c74d79813eb886d523 < 9a77f296aff4b2ca5f2928ab3a3220c82d8b4074affected
LinuxLinux881559af5f5c545f6828e7c74d79813eb886d523 < 2f5d635ad5906b0235bc0c870e8beba3116e1e98affected
LinuxLinuxd948e1ffa1d40240d5c81af6dcbcb87b39cb8d3caffected
LinuxLinux5dd0bd277a0a936708a33ecc447dce77a08cbde6affected
LinuxLinux6.6.51 < 6.7affected
LinuxLinux6.8.9 < 6.9affected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux7.1.8 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References