Executive brief
A vulnerability in the Linux kernel's Bluetooth subsystem could allow a nearby attacker to cause a system crash. The issue occurs when the system attempts to abort a pending Bluetooth connection, leading to a memory error. This primarily impacts the availability of the affected device, potentially causing a blue screen or kernel panic during Bluetooth operations.
Technical details
A vulnerability exists in the Bluetooth HCI connection management (hci_conn.c) of the Linux kernel. The function hci_abort_conn() attempts to read from hdev->sent_cmd when a connection is pending; however, hdev->sent_cmd can be NULL even while req_status is set to HCI_REQ_PEND. This race condition leads to a NULL pointer dereference and a general protection fault within the hci_rx_work() receive path. The fix introduces a new HCI_CONN_CREATE flag to track in-flight connection commands and ensures proper reference counting to prevent use-after-free scenarios during connection cleanup. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.10, 6.9, 6.6, 6.1, 5.15, 5.10, 5.4, 4.19
Timeline
- 2026-06-15: other: Vulnerability fixed in source code
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a
- https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348
- https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819
- https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2
- https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0
- https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1