Executive brief
A vulnerability in the Linux kernel's Bluetooth subsystem could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system handles Bluetooth connection parameters without proper locking, leading to a memory error. This affects devices running various versions of the Linux operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel Bluetooth subsystem within the 'set_cig_params_sync' function in 'net/bluetooth/hci_conn.c'. The root cause is a lack of proper synchronization; 'hci_conn' lookups and field accesses were not protected by the 'hdev' lock, allowing the connection object to be freed concurrently by another process. A local attacker can exploit this race condition to trigger a kernel panic or achieve arbitrary code execution. The fix involves wrapping the lookup and configuration logic with 'hci_dev_lock' to ensure atomicity and prevent concurrent modification or deletion.
Affected products
- Linux Linux Kernel 6.4.16 to 6.5, 6.5.3 to 6.6, 6.6 to 6.12.81, 6.18.22, 6.19.12
Timeline
- 2026-05-01: disclosed: Initial publication date
- 2026-04-11: patched: Patches applied to stable branches
References
- https://git.kernel.org/stable/c/66d432e9b45bae7881ffcdb12cd8fd0bf254ef02
- https://git.kernel.org/stable/c/7502c1cf303b69f71d085f5ff7251b0e1b0f09df
- https://git.kernel.org/stable/c/7d568fede8eac91161a60b710aa920abe9b0fb9f
- https://git.kernel.org/stable/c/a2639a7f0f5bf7d73f337f8f077c19415c62ed2c
- https://git.kernel.org/stable/c/bad65b4b0a96139f023eadc28a33125963208449