8.8

CVE-2026-74530

Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback

There is theoretical UAF if the conn is freed while the hci_sync task is
running.

Hold refcount to avoid that. Handle NULL hcon, return 0 + do nothing to
match the previous behavior.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 024421cf39923927ab2b5fe895d1d922b9abe67f
Version < 2d91e6244b69d752503b2d44020d8b0e323dbd38
Status affected
Version 024421cf39923927ab2b5fe895d1d922b9abe67f
Version < 56e78b670356caab0b607e8aad4cf819a1909d07
Status affected
Version 620810ac1f7f1133a9ac403e132b3ad6995ddf39
Status affected
Version ee0586ad64a805eaf1a9a10100e908627a561e34
Status affected
Version 6.12.28
Version < 6.13
Status affected
Version 6.14.6
Version < 6.15
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.126
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2d91e6244b69d752503b2d44020d8b0e323dbd38
https://git.kernel.org/stable/c/56e78b670356caab0b607e8aad4cf819a1909d07