-

CVE-2026-80764

Medienbericht

Bluetooth: hci_event: fix LE list UAF on reset

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_event: fix LE list UAF on reset

hci_cc_reset() clears the LE accept and resolving lists without taking
hdev->lock. Other command-complete handlers serialize updates to these
lists with that lock, and the debugfs readers hold it while walking them.

This permits the reset completion and a debugfs read to interleave as
follows:

  hci_rx_work                 debugfs reader
  -----------                 --------------
                              lock hdev->lock
                              fetch current entry
  list_del(entry)
  kfree(entry)
                              read entry fields

The reader then dereferences a freed list entry and may follow its stale
next pointer.

KASAN reported:

  BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180
  Read of size 1 at addr ffff8881015dab16 by task poc/95

  Call Trace:
   white_list_show+0x15f/0x180
   seq_read_iter+0x3ff/0x1190
   seq_read+0x267/0x3d0
   vfs_read+0x177/0xa20
   ksys_read+0xf7/0x1c0

  Allocated by task 91:
   hci_bdaddr_list_add+0x1a6/0x3a0
   hci_cc_le_add_to_accept_list+0xab/0x140
   hci_cmd_complete_evt+0x26c/0x9a0
   hci_event_packet+0x454/0xb20
   hci_rx_work+0x293/0x730

  Freed by task 90:
   kfree+0x131/0x3c0
   hci_bdaddr_list_clear+0xd8/0x160
   hci_cc_reset+0x28a/0x370
   hci_cmd_complete_evt+0x26c/0x9a0
   hci_event_packet+0x454/0xb20
   hci_rx_work+0x293/0x730

Take hdev->lock around both list clears. This matches the existing
mutation and traversal locking convention.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < 8e68c380290b1dd64a0a512ce66d0264130c46ed
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < 0628cc9b2fa29985a7b8c774741f8a736b0f5e7c
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < d57702d4c55633c243da5a2fec37ae2ad4adb621
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < 39a3afb91be3cb465f46ce7a8e5696d9e33edf93
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < b55e83a4ba31d40deae22d4e4dc8c84083e953c6
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < 25b05e3ce31d954540e99954bcc66cbceb27ab35
Status affected
Version a4d5504d5c39cc84f1f828e19967595597a8136e
Version < 33af47e847fe4a28b109673affb5874015d54f5a
Status affected
Version 0de8cd646b0152c9ddd10257d8284938d0df0181
Status affected
Version 3.18.3
Version < 3.19
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.19
Status affected
Version 0
Version < 3.19
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/8e68c380290b1dd64a0a512ce66d0264130c46ed
https://git.kernel.org/stable/c/0628cc9b2fa29985a7b8c774741f8a736b0f5e7c
https://git.kernel.org/stable/c/d57702d4c55633c243da5a2fec37ae2ad4adb621
https://git.kernel.org/stable/c/39a3afb91be3cb465f46ce7a8e5696d9e33edf93
https://git.kernel.org/stable/c/b55e83a4ba31d40deae22d4e4dc8c84083e953c6
https://git.kernel.org/stable/c/25b05e3ce31d954540e99954bcc66cbceb27ab35
https://git.kernel.org/stable/c/33af47e847fe4a28b109673affb5874015d54f5a