Bluetooth: coredump: Quiesce dump work on unregister
Summary
| CVE | CVE-2026-98295 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:20 UTC |
| Updated | 2026-10-06 09:18:20 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: coredump: Quiesce dump work on unregister hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it. Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge. |
Risk And Classification
EPSS: 0.001750000 probability, percentile 0.063840000 (date 2026-10-06)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 9695ef876fd122cb7bbc04a4a93b8727d2e36bda 24af375d7d8aa5f698e4dc41317102f44114351a git | Not specified |
| CNA | Linux | Linux | affected 9695ef876fd122cb7bbc04a4a93b8727d2e36bda dcaf10ef27f928568c25de3e9fc242e538de5c67 git | Not specified |
| CNA | Linux | Linux | affected 9695ef876fd122cb7bbc04a4a93b8727d2e36bda 82699d1b727ba5980b94f1eb8dc3d346f41b7c67 git | Not specified |
| CNA | Linux | Linux | affected 9695ef876fd122cb7bbc04a4a93b8727d2e36bda d236517c264e41dc09833c708ef23bccb7a91219 git | Not specified |
| CNA | Linux | Linux | affected deb8156ebe5cb63a5988e7f86cc46aa062527c2b git | Not specified |
| CNA | Linux | Linux | affected 6.1.188 6.2 semver | Not specified |
| CNA | Linux | Linux | affected 6.4 | Not specified |
| CNA | Linux | Linux | unaffected 6.4 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.112 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.54 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.8 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.