๐Ÿ” CVE Alert

CVE-2026-64406

UNKNOWN 0.0

Bluetooth: fix UAF in bt_accept_dequeue()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
751de6ec671fe75ad9cf65a0638d2a06b6a5984d < c0577c55219be42b6ea2ea8db11e85bfab6f4e8d 407217734835d21d4e0105ebf347860dc1806f88 < 96ad400d5132eb333f28f6f1e2d58f0728ca9547 7eebd4c2c86f573af87ff165d08a83432eb0b919 < 0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0 5d86d2f1b4d9a508c441d3e45277ae1a73cfed57 < c66a95e60b65d876a927123b0ed36bd6177d9ca6 87c543e2f78d0871f271df92dab98901bbd5b6f5 < 6303ed4bbe0095f4cc195225479bf506e010d1db added1213395071470a900cc845a042fb51882a6 < 26168db1ce5a9766cde021b18e590a101c056614 ab1513597c6cf17cd1ad2a21e3b045421b48e022 < 50c662bdcd51b03033a0abed6716bfd377ba1049 ab1513597c6cf17cd1ad2a21e3b045421b48e022 < 4bd0b274054f2679f28b70222b607bb0afc3ab9a a5ca86a6097a8b030ca3226cd300b17ed330f966 5.10.259 < 5.10.261 5.15.210 < 5.15.212 6.1.175 < 6.1.178 6.6.142 < 6.6.145 6.12.92 < 6.12.96 6.18.34 < 6.18.39 7.0.11 < 7.1
Linux / Linux
7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c0577c55219be42b6ea2ea8db11e85bfab6f4e8d git.kernel.org: https://git.kernel.org/stable/c/96ad400d5132eb333f28f6f1e2d58f0728ca9547 git.kernel.org: https://git.kernel.org/stable/c/0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0 git.kernel.org: https://git.kernel.org/stable/c/c66a95e60b65d876a927123b0ed36bd6177d9ca6 git.kernel.org: https://git.kernel.org/stable/c/6303ed4bbe0095f4cc195225479bf506e010d1db git.kernel.org: https://git.kernel.org/stable/c/26168db1ce5a9766cde021b18e590a101c056614 git.kernel.org: https://git.kernel.org/stable/c/50c662bdcd51b03033a0abed6716bfd377ba1049 git.kernel.org: https://git.kernel.org/stable/c/4bd0b274054f2679f28b70222b607bb0afc3ab9a