Junglewise Threat Intelligence

CVE-2026-64405: Linux Kernel NULL pointer dereference in Bluetooth hci_abort_conn

CVE-2026-64405 · Severity: info · CVSS 6.8 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth subsystem could allow a nearby attacker to cause a system crash. The issue occurs when the system attempts to abort a pending Bluetooth connection, leading to a memory error. This primarily impacts the availability of the affected device, potentially causing a blue screen or kernel panic during Bluetooth operations.

Technical details

A vulnerability exists in the Bluetooth HCI connection management (hci_conn.c) of the Linux kernel. The function hci_abort_conn() attempts to read from hdev->sent_cmd when a connection is pending; however, hdev->sent_cmd can be NULL even while req_status is set to HCI_REQ_PEND. This race condition leads to a NULL pointer dereference and a general protection fault within the hci_rx_work() receive path. The fix introduces a new HCI_CONN_CREATE flag to track in-flight connection commands and ensures proper reference counting to prevent use-after-free scenarios during connection cleanup. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.10, 6.9, 6.6, 6.1, 5.15, 5.10, 5.4, 4.19

Timeline

  • 2026-06-15: other: Vulnerability fixed in source code
  • 2026-07-25: disclosed: CVE published

References