Junglewise Threat Intelligence

CVE-2026-64470: Linux Kernel btusb use-after-free in Marvell probe failure

CVE-2026-64470 · Severity: info · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth USB driver (btusb) affecting systems using Marvell Bluetooth hardware. During the initial setup of the device, a failure could lead to a 'use-after-free' condition, which typically results in a system crash or could potentially be exploited to gain unauthorized control over the system. This issue occurs specifically when the system fails to properly clean up communication requests during a hardware initialization error.

Technical details

A use-after-free vulnerability exists in drivers/bluetooth/btusb.c within the Linux kernel. The flaw is triggered during the btusb_probe sequence for Marvell devices when TX URBs (USB Request Blocks) are submitted for Out-of-Band (OOB) wakeup configuration. If the probe process subsequently fails, these URBs are not properly cancelled or 'killed,' leading to a completion callback attempting to access memory that has already been freed. An attacker with the ability to trigger device probing or hardware initialization failures could potentially cause a kernel panic or execute arbitrary code. The fix involves ensuring usb_kill_anchored_urbs is called on the tx_anchor during error paths.

Affected products

  • Linux Linux Kernel 4.11 to 5.10.261, 5.15.212, 6.1.178, 6.6.145

Timeline

  • 2026-07-25: advisory
  • 2026-07-24: patched

References

Related threats