Junglewise Threat Intelligence

CVE-2026-46056: Linux Kernel use-after-free in Bluetooth SSP passkey handlers

CVE-2026-46056 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's Bluetooth subsystem. This flaw could allow a nearby attacker to cause a system crash or potentially execute unauthorized code by exploiting a race condition during the Bluetooth pairing process. The issue specifically affects how the system handles passkey notifications when connecting to other Bluetooth devices.

Technical details

A use-after-free (UAF) vulnerability exists in net/bluetooth/hci_event.c within the hci_user_passkey_notify_evt() and hci_keypress_notify_evt() functions. The root cause is a race condition where hci_conn lookup and field access are performed without holding the hdev lock, allowing the connection object to be freed concurrently by another thread. An attacker can trigger this by initiating or manipulating Bluetooth pairing events. The fix involves extending the hci_dev_lock critical section to encompass all connection object usage within these handlers. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel All versions prior to the fixed commits in 6.1, 6.6, 6.8, and 6.9 branches

Timeline

  • 2026-04-09: other: Patch authored
  • 2026-05-27: advisory: CVE published

References

Related threats