Bluetooth: hci_sync: extend conn_hash lookup critical sections
Summary
| CVE | CVE-2026-68393 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:32 UTC |
| Updated | 2026-08-10 13:20:32 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: extend conn_hash lookup critical sections
Using RCU-protected pointers outside the critical sections without
refcount is incorrect and may result to UAF.
Extend critical section to cover both hci_conn_hash lookup and use of
the returned conn.
Add surrounding rcu_read_lock() also when return value is not used, in
preparation for RCU lockdep requirement to hci_lookup_le_connect().
This avoids concurrent deletion of the conn before we are done
dereferencing it.
Also, make sure to hold hdev->lock when accessing hdev->accept_list. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 6d0417e4e1cf66fd917f06f0454958362714ef7d 83b7e67698d0b93f685875ce82c8d335436834f7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6d0417e4e1cf66fd917f06f0454958362714ef7d 38326774df6198df0cc2744cc73bf77cb741c538 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6d0417e4e1cf66fd917f06f0454958362714ef7d d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d git |
Not specified |
| CNA |
Linux |
Linux |
affected eb8b860e87b296bd1874c79a668081efd00f9754 git |
Not specified |
| CNA |
Linux |
Linux |
affected 94bf6380e936339a700c0b3171a49baf512aa70b git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.28 6.13 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.14.6 6.15 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.15 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.15 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/83b7e67698d0b93f685875ce82c8d335436834f7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/38326774df6198df0cc2744cc73bf77cb741c538 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.