Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth USB driver (btusb) affecting systems using Marvell Bluetooth hardware. During the initial setup of the device, a failure could lead to a 'use-after-free' condition, which typically results in a system crash or could potentially be exploited to gain unauthorized control over the system. This issue occurs specifically when the system fails to properly clean up communication requests during a hardware initialization error.
Technical details
A use-after-free vulnerability exists in drivers/bluetooth/btusb.c within the Linux kernel. The flaw is triggered during the btusb_probe sequence for Marvell devices when TX URBs (USB Request Blocks) are submitted for Out-of-Band (OOB) wakeup configuration. If the probe process subsequently fails, these URBs are not properly cancelled or 'killed,' leading to a completion callback attempting to access memory that has already been freed. An attacker with the ability to trigger device probing or hardware initialization failures could potentially cause a kernel panic or execute arbitrary code. The fix involves ensuring usb_kill_anchored_urbs is called on the tx_anchor during error paths.
Affected products
- Linux Linux Kernel 4.11 to 5.10.261, 5.15.212, 6.1.178, 6.6.145
Timeline
- 2026-07-25: advisory
- 2026-07-24: patched
References
- https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4
- https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed
- https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8
- https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af
- https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a
- https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e
- https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2