CVE-2026-98295

Summary

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux9695ef876fd122cb7bbc04a4a93b8727d2e36bda < 24af375d7d8aa5f698e4dc41317102f44114351aaffected
LinuxLinux9695ef876fd122cb7bbc04a4a93b8727d2e36bda < dcaf10ef27f928568c25de3e9fc242e538de5c67affected
LinuxLinux9695ef876fd122cb7bbc04a4a93b8727d2e36bda < 82699d1b727ba5980b94f1eb8dc3d346f41b7c67affected
LinuxLinux9695ef876fd122cb7bbc04a4a93b8727d2e36bda < d236517c264e41dc09833c708ef23bccb7a91219affected
LinuxLinuxdeb8156ebe5cb63a5988e7f86cc46aa062527c2baffected
LinuxLinux6.1.188 < 6.2affected
LinuxLinux6.4affected
LinuxLinux0 < 6.4unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References