Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error

Summary

CVECVE-2026-53073
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-24 17:17:21 UTC
Updated2026-06-24 17:17:21 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to NULL. This means incoming UART data will reach the protocol-specific recv handler in hci_uart_tty_receive() after resources are freed. Clear HCI_UART_PROTO_INIT with a write lock before calling hu->proto->close() and setting hu->hdev to NULL. The write lock ensures all active readers have completed and no new reader can enter the protocol recv path before resources are freed. This allows the protocol-specific recv functions to remove the "HCI_UART_REGISTERED" guard without risking a null pointer dereference if hci_register_dev() fails.

Risk And Classification

EPSS: 0.001720000 probability, percentile 0.068050000 (date 2026-06-26)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected a40f94f7caa8d3421b64f63ac31bc0f24c890f39 ebb39b2d81731b83ee71a1ba6dd0291a57b5ac07 git Not specified
CNA Linux Linux affected 9e5a0f5777162e503400c70c6ed25fbbe2d38799 ed4033fb85ccaaf6c3983be3c7b037e48253d232 git Not specified
CNA Linux Linux affected 80f14e9de6a43a0bd8194cad1003a3e6dcbc3984 356dee1bcac4d0d9152390561fa63331ebff211b git Not specified
CNA Linux Linux affected 02e1bcdfdf769974e7e9fa285e295cd9852e2a38 a673cf6c4ac702cb79ac1f4d7fc4de763a6a3e40 git Not specified
CNA Linux Linux affected 281782d2c6730241e300d630bb9f200d831ede71 f4b69c35813c432973d340d3600c01de106ed474 git Not specified
CNA Linux Linux affected 5df5dafc171b90d0b8d51547a82657cd5a1986c7 3daa5818e473ed60eb69d8b5c71b651909d28c5a git Not specified
CNA Linux Linux affected 5df5dafc171b90d0b8d51547a82657cd5a1986c7 194f029a4d7f739e44ebc1f473120187b4de5104 git Not specified
CNA Linux Linux affected 5df5dafc171b90d0b8d51547a82657cd5a1986c7 68d39ea5e0adc9ecaea1ce8abd842ec972eb8718 git Not specified
CNA Linux Linux affected 1dcf08fcff5ca529de6dc0395091f28854f4e54a git Not specified
CNA Linux Linux affected 8e5aff600539e5faea294d9612cca50220e602b8 git Not specified
CNA Linux Linux affected db7509fa110dd9b11134b75894677f30353b2c51 git Not specified
CNA Linux Linux affected 5.10.237 5.10.258 semver Not specified
CNA Linux Linux affected 5.15.181 5.15.209 semver Not specified
CNA Linux Linux affected 6.1.135 6.1.175 semver Not specified
CNA Linux Linux affected 6.6.88 6.6.141 semver Not specified
CNA Linux Linux affected 6.12.24 6.12.91 semver Not specified
CNA Linux Linux affected 5.4.293 5.5 semver Not specified
CNA Linux Linux affected 6.13.12 6.14 semver Not specified
CNA Linux Linux affected 6.14.3 6.15 semver Not specified
CNA Linux Linux affected 6.15 Not specified
CNA Linux Linux unaffected 6.15 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.141 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.91 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.33 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.10 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/3daa5818e473ed60eb69d8b5c71b651909d28c5a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/194f029a4d7f739e44ebc1f473120187b4de5104 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/356dee1bcac4d0d9152390561fa63331ebff211b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/68d39ea5e0adc9ecaea1ce8abd842ec972eb8718 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a673cf6c4ac702cb79ac1f4d7fc4de763a6a3e40 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ed4033fb85ccaaf6c3983be3c7b037e48253d232 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ebb39b2d81731b83ee71a1ba6dd0291a57b5ac07 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f4b69c35813c432973d340d3600c01de106ed474 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report