Bluetooth: mgmt: fix pending command UAF in EIR updates
Summary
| CVE | CVE-2026-74511 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:56 UTC |
| Updated | 2026-08-15 13:17:56 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix pending command UAF in EIR updates
MGMT_OP_SET_LOCAL_NAME is handled asynchronously on powered controllers
and can run set_name_sync(). When the controller is BR/EDR capable,
set_name_sync() updates the local name and then rebuilds EIR data through
eir_create(). The EIR builder walks hdev->uuids, but the UUID list can
be changed and entries can be freed by MGMT_OP_ADD_UUID and
MGMT_OP_REMOVE_UUID.
pending_eir_or_class() is meant to serialize management commands that
can change EIR or the class of device, but it did not include
MGMT_OP_SET_LOCAL_NAME. In addition, it walked hdev->mgmt_pending
without hdev->mgmt_pending_lock even though pending commands are added
and removed under that mutex. A racing command completion can therefore
remove and free a pending command while pending_eir_or_class() is still
inspecting it, leading to a use-after-free in the pending-command list or
allowing a local name update to rebuild EIR while UUID entries are being
removed.
Take hdev->mgmt_pending_lock while scanning hdev->mgmt_pending and treat
MGMT_OP_SET_LOCAL_NAME as an EIR/class-affecting pending command on the
powered asynchronous path. Check for a conflicting pending command before
copying the new short name so a rejected SET_LOCAL_NAME request does not
modify hdev->short_name. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected bdd56875c6926d8009914f427df71797693e90d4 a9e7c2609b0cb3fb4b4ba9f66dd8727d33205967 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4e83f2dbb2bf677e614109df24426c4dded472d4 eacfcb6b735d0e16b4d2ecfde4b9141225ee934e git |
Not specified |
| CNA |
Linux |
Linux |
affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 814f82f432dc6ee4d15f94756554ff94e6e3ef05 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 35464ff818165131464bd524c259db1ac8044ae3 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6fe26f694c824b8a4dbf50c635bee1302e3f099c 8f2f62855a41d1730fb9e8122912bd2c8d6bed5d git |
Not specified |
| CNA |
Linux |
Linux |
affected d7882db79135c829a922daf3571f33ea1e056ae3 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.94 6.6.151 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.34 6.12.103 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.15.3 6.16 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.16 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.16 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.151 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/8f2f62855a41d1730fb9e8122912bd2c8d6bed5d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a9e7c2609b0cb3fb4b4ba9f66dd8727d33205967 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/eacfcb6b735d0e16b4d2ecfde4b9141225ee934e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/35464ff818165131464bd524c259db1ac8044ae3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/814f82f432dc6ee4d15f94756554ff94e6e3ef05 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.