8.8
CVE-2026-74509
- EPSS 0.24%
- Veröffentlicht 15.08.2026 12:27:31
- Zuletzt bearbeitet 23.08.2026 13:16:45
- CVE-Watchlists
- Unerledigt
Bluetooth: hci_sync: Fix advertising data UAFs
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Fix advertising data UAFs
hci_find_adv_instance() returns an adv_info pointer that is valid only
while hdev->lock is held. The advertising command-sync paths perform
instance lookups without that lock and, in some cases, retain the pointer
while waiting for a controller response.
An advertising termination event can therefore interleave as follows:
hci_cmd_sync_work hci_rx_work
hci_find_adv_instance()
__hci_cmd_sync_status()
wait for controller reply hci_dev_lock()
hci_remove_adv_instance()
kfree(adv)
adv->scan_rsp_changed = false
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
hci_schedule_adv_instance_sync+0x390/0x4c0
hci_cmd_sync_work+0x173/0x300
Allocated by task 87:
hci_add_adv_instance+0x538/0xac0
add_advertising+0x885/0x1160
Freed by task 89:
kfree+0x131/0x3c0
hci_remove_adv_instance+0x1d8/0x3b0
hci_le_ext_adv_term_evt+0x17b/0x730
Protect the instance lookup and payload construction in the extended
advertising, scan response, and periodic advertising data paths. Snapshot
the advertising parameters under hdev->lock, but release the lock before
waiting for the controller.
Clear advertising-data dirty bits before issuing their commands and
restore them after a failure using a fresh lookup. Likewise, update the
reported transmit power through a fresh lookup after the parameter command
completes. No adv_info pointer then survives an HCI command wait.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
cba6b758711cab946c787f7c15be92cc749b8e1f
Version <
565971488191bf54a87a417abafab6ad0de72201
Status
affected
Version
cba6b758711cab946c787f7c15be92cc749b8e1f
Version <
95cdcd8c82a501931fd3ae9b3811b0b6da167e94
Status
affected
Version
cba6b758711cab946c787f7c15be92cc749b8e1f
Version <
eb1d8318764de7216e6dbba29a24d69f7ce51348
Status
affected
Version
cba6b758711cab946c787f7c15be92cc749b8e1f
Version <
b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3
Status
affected
Version
cba6b758711cab946c787f7c15be92cc749b8e1f
Version <
cdc36db204ffd97b947d64374cf23a210dc74777
Status
affected
Version
42fe380baaaccbe635c34ca07b29d19b9ec2498d
Status
affected
Version
5.15.210
Version <
5.16
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.17
Status
affected
Version
0
Version <
5.17
Status
unaffected
Version <=
6.1.*
Version
6.1.184
Status
unaffected
Version <=
6.12.*
Version
6.12.103
Status
unaffected
Version <=
6.18.*
Version
6.18.44
Status
unaffected
Version <=
7.1.*
Version
7.1.8
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.146 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/95cdcd8c82a501931fd3ae9b3811b0b6da167e94
https://git.kernel.org/stable/c/eb1d8318764de7216e6dbba29a24d69f7ce51348
https://git.kernel.org/stable/c/b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3
https://git.kernel.org/stable/c/cdc36db204ffd97b947d64374cf23a210dc74777
https://git.kernel.org/stable/c/565971488191bf54a87a417abafab6ad0de72201