๐Ÿ” CVE Alert

CVE-2026-74540

HIGH 8.8

Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp

CVSS Score
8.8
EPSS Score
0.2%
EPSS Percentile
16th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp l2cap_le_connect_rsp() obtains a channel via __l2cap_get_chan_by_ident() but neither holds a reference nor uses l2cap_chan_hold_unless_zero() before locking and operating on it. A concurrent l2cap_chan_del() triggered by a remote disconnect can free the channel between the lookup and l2cap_chan_lock(), causing a use-after-free. The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero() to safely hold a reference, but l2cap_le_connect_rsp() was left unprotected. Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup and l2cap_chan_put() on the exit path, consistent with other L2CAP response handlers.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 15d6c2367217a6a20b1abae9f38ded716bf620f1 f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 1818180fe12d6cec7a437bc59cde8efdf6b10250 f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 8325eafb38c3dee5af329266393763693d17381b f1496dee9cbde2a62821f4441dadb0d3360f60c3 < fd4c1e301bdec60a40728ea37de531cbccda501a f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 522b730c62c53a1981604fd73524697fd347830d f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136 f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 09f447accc2570751e7d17f0dc0788b40d3edade f1496dee9cbde2a62821f4441dadb0d3360f60c3 < c4740e7f23ff9a8210198d8b4703259e21b9f69d
Linux / Linux
3.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/15d6c2367217a6a20b1abae9f38ded716bf620f1 git.kernel.org: https://git.kernel.org/stable/c/1818180fe12d6cec7a437bc59cde8efdf6b10250 git.kernel.org: https://git.kernel.org/stable/c/8325eafb38c3dee5af329266393763693d17381b git.kernel.org: https://git.kernel.org/stable/c/fd4c1e301bdec60a40728ea37de531cbccda501a git.kernel.org: https://git.kernel.org/stable/c/522b730c62c53a1981604fd73524697fd347830d git.kernel.org: https://git.kernel.org/stable/c/58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136 git.kernel.org: https://git.kernel.org/stable/c/09f447accc2570751e7d17f0dc0788b40d3edade git.kernel.org: https://git.kernel.org/stable/c/c4740e7f23ff9a8210198d8b4703259e21b9f69d