Back to overview

CVE-2026-64406

Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.

Metadata

CVE ID
CVE-2026-64406
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:50 UTC
Last updated
2026-07-25 08:50 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 751de6ec671fe75ad9cf65a0638d2a06b6a5984d < c0577c55219be42b6ea2ea8db11e85bfab6f4e8d, 407217734835d21d4e0105ebf347860dc1806f88 < 96ad400d5132eb333f28f6f1e2d58f0728ca9547, 7eebd4c2c86f573af87ff165d08a83432eb0b919 < 0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0, 5d86d2f1b4d9a508c441d3e45277ae1a73cfed57 < c66a95e60b65d876a927123b0ed36bd6177d9ca6 …
Linux Linux 7.1, 0 < 7.1, 5.10.261 ≤ 5.10.*, 5.15.212 ≤ 5.15.* …
Back to overview