CVE-2026-97977
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: Fix UAF of btusb_data by rx_work
btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.
btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data:
while ((skb = skb_dequeue(&data->acl_q)))
data->recv_acl(data->hdev, skb);
Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 800fe5ec302e1ebbf5e3f891f886deecd49c7132 < 472d005622525b7be155cac99dde2252b0163bd1 | affected |
| Linux | Linux | 800fe5ec302e1ebbf5e3f891f886deecd49c7132 < 93b59937bda3fffc6386c79f5544a39bc680c8e8 | affected |
| Linux | Linux | 800fe5ec302e1ebbf5e3f891f886deecd49c7132 < fa391adb9c755515a89993634745e9079e5ef37c | affected |
| Linux | Linux | 800fe5ec302e1ebbf5e3f891f886deecd49c7132 < 1c12c3117639e78940959d956519c758c57d0849 | affected |
| Linux | Linux | 5.17 | affected |
| Linux | Linux | 0 < 5.17 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/472d005622525b7be155cac99dde2252b0163bd1
- https://git.kernel.org/stable/c/93b59937bda3fffc6386c79f5544a39bc680c8e8
- https://git.kernel.org/stable/c/fa391adb9c755515a89993634745e9079e5ef37c
- https://git.kernel.org/stable/c/1c12c3117639e78940959d956519c758c57d0849
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.