8.8
CVE-2026-64408
- EPSS 0.26%
- Veröffentlicht 25.07.2026 08:50:49
- Zuletzt bearbeitet 17.08.2026 05:17:44
- CVE-Watchlists
- Unerledigt
Bluetooth: bnep: pin L2CAP connection during netdev registration
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
390b5db3ff8745187f094c4e915663b7b1f98944
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
46a88784c4c9b96954dd86f747ce93f65efa1302
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
551ae773ec64045b4e72099132654887e0270bcc
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
ae215c5b6422d8eda443b861b124bd1be6969c31
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
df22adc7eafc22e651561813c11dc51a796b12ee
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
a6b22dbd80926556290ad2243be25218d6956a19
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
563a8573047182f550b1e1e030615755cd8c41da
Status
affected
Version
65f53e9802dbfae0e5758a91793c3f5f8bece49b
Version <
bb067a99a0356196c0b89a95721985485ebce5a5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.13
Status
affected
Version
0
Version <
3.13
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.96
Status
unaffected
Version <=
6.18.*
Version
6.18.39
Status
unaffected
Version <=
7.1.*
Version
7.1.4
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.179 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/390b5db3ff8745187f094c4e915663b7b1f98944
https://git.kernel.org/stable/c/46a88784c4c9b96954dd86f747ce93f65efa1302
https://git.kernel.org/stable/c/551ae773ec64045b4e72099132654887e0270bcc
https://git.kernel.org/stable/c/ae215c5b6422d8eda443b861b124bd1be6969c31
https://git.kernel.org/stable/c/df22adc7eafc22e651561813c11dc51a796b12ee
https://git.kernel.org/stable/c/a6b22dbd80926556290ad2243be25218d6956a19
https://git.kernel.org/stable/c/563a8573047182f550b1e1e030615755cd8c41da
https://git.kernel.org/stable/c/bb067a99a0356196c0b89a95721985485ebce5a5