Junglewise Threat Intelligence

CVE-2026-31511: Linux Kernel use-after-free in Bluetooth MGMT monitor

CVE-2026-31511 · Severity: high · CVSS 7.8 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth management component could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system handles Bluetooth advertising monitors, where a technical error can leave a 'dangling pointer' in the system's memory. This could lead to a system instability or a security breach if the memory is accessed after being freed.

Technical details

A use-after-free (UAF) vulnerability exists in net/bluetooth/mgmt.c within the mgmt_add_adv_patterns_monitor_complete function. The root cause is a flawed conditional check that fails to properly unlink a command from the pending list before freeing its memory when a specific status code (ECANCELED) is encountered. This results in a dangling pointer remaining in the mgmt_pending list. Subsequent list traversals, such as those occurring during power-off sequences or further management calls, will dereference this freed memory. An attacker with local access could exploit this to cause a kernel panic or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.12.59 to 6.12.80, 6.16.10 to 6.17, 6.17.1 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-03-16: patched: Initial fix authored by Luiz Augusto von Dentz
  • 2026-04-22: disclosed: CVE-2026-31511 published

References

Related threats