Executive brief
A flaw in Realtek's Bluetooth HCI driver violates buffer ownership rules, causing a transmitted buffer to be freed twice when errors occur—once by the driver and again by the host. This memory corruption can crash Bluetooth-enabled devices or enable further attacks. Remote Bluetooth peers can trigger the error conditions through heavy traffic.
Technical details
The vulnerability is a double-free (CWE-415) and use-after-free read (CWE-416) in the bt_hci_bee_send() function in drivers/bluetooth/hci/hci_bee.c. The driver violates the bt_hci_driver_api contract by unconditionally calling net_buf_unref() on all error paths; the host caller then unrefs the same buffer again, corrupting the net_buf pool. Additionally, error-path code dereferences buf->len after the unref, reading freed memory. The vulnerability is reachable when the controller's host-to-controller buffer allocation fails or the controller send fails (resource-exhaustion or I/O conditions). A remote Bluetooth peer can indirectly trigger these conditions via heavy host transmit activity, leading to device crashes and potential memory corruption. The fix separates success and error paths, returning early from errors without unreffing and unreffing only on success.
Affected products
- Realtek BEE Bluetooth HCI driver
Timeline
- 2026-08-11: disclosed