Bluetooth: mgmt: fix pending command UAF in EIR updates

Summary

CVECVE-2026-74511
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 13:17:56 UTC
Updated2026-08-15 13:17:56 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix pending command UAF in EIR updates MGMT_OP_SET_LOCAL_NAME is handled asynchronously on powered controllers and can run set_name_sync(). When the controller is BR/EDR capable, set_name_sync() updates the local name and then rebuilds EIR data through eir_create(). The EIR builder walks hdev->uuids, but the UUID list can be changed and entries can be freed by MGMT_OP_ADD_UUID and MGMT_OP_REMOVE_UUID. pending_eir_or_class() is meant to serialize management commands that can change EIR or the class of device, but it did not include MGMT_OP_SET_LOCAL_NAME. In addition, it walked hdev->mgmt_pending without hdev->mgmt_pending_lock even though pending commands are added and removed under that mutex. A racing command completion can therefore remove and free a pending command while pending_eir_or_class() is still inspecting it, leading to a use-after-free in the pending-command list or allowing a local name update to rebuild EIR while UUID entries are being removed. Take hdev->mgmt_pending_lock while scanning hdev->mgmt_pending and treat MGMT_OP_SET_LOCAL_NAME as an EIR/class-affecting pending command on the powered asynchronous path. Check for a conflicting pending command before copying the new short name so a rejected SET_LOCAL_NAME request does not modify hdev->short_name.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected bdd56875c6926d8009914f427df71797693e90d4 a9e7c2609b0cb3fb4b4ba9f66dd8727d33205967 git Not specified
CNA Linux Linux affected 4e83f2dbb2bf677e614109df24426c4dded472d4 eacfcb6b735d0e16b4d2ecfde4b9141225ee934e git Not specified
CNA Linux Linux affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 814f82f432dc6ee4d15f94756554ff94e6e3ef05 git Not specified
CNA Linux Linux affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 35464ff818165131464bd524c259db1ac8044ae3 git Not specified
CNA Linux Linux affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 8f2f62855a41d1730fb9e8122912bd2c8d6bed5d git Not specified
CNA Linux Linux affected d7882db79135c829a922daf3571f33ea1e056ae3 git Not specified
CNA Linux Linux affected 6.6.94 6.6.151 semver Not specified
CNA Linux Linux affected 6.12.34 6.12.103 semver Not specified
CNA Linux Linux affected 6.15.3 6.16 semver Not specified
CNA Linux Linux affected 6.16 Not specified
CNA Linux Linux unaffected 6.16 semver Not specified
CNA Linux Linux unaffected 6.6.151 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.103 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.44 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.8 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc6 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/8f2f62855a41d1730fb9e8122912bd2c8d6bed5d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a9e7c2609b0cb3fb4b4ba9f66dd8727d33205967 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/eacfcb6b735d0e16b4d2ecfde4b9141225ee934e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/35464ff818165131464bd524c259db1ac8044ae3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/814f82f432dc6ee4d15f94756554ff94e6e3ef05 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report