Executive brief
A vulnerability in the Linux kernel's Bluetooth management component could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system handles Bluetooth advertising monitors, where a technical error can leave a 'dangling pointer' in the system's memory. This could lead to a system instability or a security breach if the memory is accessed after being freed.
Technical details
A use-after-free (UAF) vulnerability exists in net/bluetooth/mgmt.c within the mgmt_add_adv_patterns_monitor_complete function. The root cause is a flawed conditional check that fails to properly unlink a command from the pending list before freeing its memory when a specific status code (ECANCELED) is encountered. This results in a dangling pointer remaining in the mgmt_pending list. Subsequent list traversals, such as those occurring during power-off sequences or further management calls, will dereference this freed memory. An attacker with local access could exploit this to cause a kernel panic or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.12.59 to 6.12.80, 6.16.10 to 6.17, 6.17.1 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc7
Timeline
- 2026-03-16: patched: Initial fix authored by Luiz Augusto von Dentz
- 2026-04-22: disclosed: CVE-2026-31511 published
References
- https://git.kernel.org/stable/c/2074dfffad76981ca451cb7fc98703d04ac562fe
- https://git.kernel.org/stable/c/340666172cf747de58c283d2eef1f335f050538b
- https://git.kernel.org/stable/c/3a89c33deffb3cb7877a7ea2e50734cd12b064f2
- https://git.kernel.org/stable/c/5f5fa4cd35f707344f65ce9e225b6528691dbbaa
- https://git.kernel.org/stable/c/bafec9325d4de26b6c49db75b5d5172de652aae0