Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Summary
| CVE | CVE-2026-68392 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:32 UTC |
| Updated | 2026-08-10 13:20:32 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.
Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU
to ensure the conn is fully initialized at this point. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c 8bc83f9ef6789571f399ff631a2a14a12b6d8585 git |
Not specified |
| CNA |
Linux |
Linux |
affected 227a0cdf4a028a73dc256d0f5144b4808d718893 579faba5ede6df6b7f36777c431dc8dcf9d272e7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 227a0cdf4a028a73dc256d0f5144b4808d718893 ca58ad287bfc5b9d31a72ecb8650289df2b57250 git |
Not specified |
| CNA |
Linux |
Linux |
affected 227a0cdf4a028a73dc256d0f5144b4808d718893 b11511006f9e17000de3f4cadee451364f658ca3 git |
Not specified |
| CNA |
Linux |
Linux |
affected 227a0cdf4a028a73dc256d0f5144b4808d718893 16cd66443957e4ad42155c6fec401012f600c6f8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 58afdc9b18871eb1d461c725be9e9f3f44a39aeb git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.51 6.6.148 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.10.10 6.11 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.11 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.11 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/579faba5ede6df6b7f36777c431dc8dcf9d272e7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8bc83f9ef6789571f399ff631a2a14a12b6d8585 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/16cd66443957e4ad42155c6fec401012f600c6f8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b11511006f9e17000de3f4cadee451364f658ca3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ca58ad287bfc5b9d31a72ecb8650289df2b57250 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.