Executive brief
The Linux kernel's Bluetooth subsystem contains a use-after-free vulnerability in the hci_unregister_dev() function that fails to properly disable timers before freeing memory. If a timer fires during device teardown, it dereferences freed memory structures, potentially allowing local code execution or system crashes on systems with Bluetooth hardware.
Technical details
The vulnerability is a use-after-free (CWE-416) in net/bluetooth/hci_core.c's hci_unregister_dev() function. The root cause is that cmd_timer and ncmd_timer delayed work timers are not disabled before the hci_dev structure is freed. If either timer fires during device teardown, the callback handler dereferences freed memory, including the hdev->reset function pointer, leading to potential code execution. The fix adds disable_delayed_work_sync() calls for both timers to ensure they are fully quiesced before proceeding with teardown. This is a local vulnerability requiring device access or driver interaction.
Affected products
- Linux Linux kernel multiple versions (Bluetooth hci_core subsystem)
Timeline
- 2026-08-15: disclosed: CVE-2026-74302 published
- 2026-06-11: patched: Fix committed upstream (commit 5edcc018fa6e80b2c478454a4a8229c23d67c181)
- 2026-07-24: patched: Fix committed to stable trees