Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_core: Fix UAF in hci_unregister_dev()

hci_unregister_dev() does not disable cmd_timer and ncmd_timer
before the hci_dev structure is freed. If a timeout fires
during device teardown, the callback dereferences freed memory
(including the hdev->reset function pointer), leading to a
use-after-free.

Add disable_delayed_work_sync() calls alongside the existing
disable_work_sync() calls to ensure both timers are fully
quiesced before teardown proceeds.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free condition in the Bluetooth core of the Linux kernel. During device teardown, hci_unregister_dev() fails to stop the cmd_timer and ncmd_timer before freeing the hci_dev structure. If a timer expires while the structure is still referenced, the callback accesses freed memory, in particular the hdev->reset function pointer. This results in kernel memory corruption and can allow an attacker to execute arbitrary code in kernel mode.

Affected Systems

The vulnerability is present in the generic hci_core code of the Linux kernel. It affects any Linux distribution that ships a kernel version before the commit that introduces disable_delayed_work_sync() calls. Therefore, all systems running an unpatched Linux kernel that supports Bluetooth hardware are potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 places this flaw in the high‑severity range. The EPSS score of <1% indicates a low but nonzero likelihood of exploitation in the wild. Because it is not listed in the CISA KEV catalog, no known active exploits are reported. Nevertheless, the flaw resides in privileged kernel code; a local attacker with sufficient access could potentially trigger the use‑after‑free and gain kernel‑level execution. The overall risk remains moderate until the patch is applied.

Generated by OpenCVE AI on August 22, 2026 at 02:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the commit 48c7ad6afcc58c2cda11fed39791708103b6a644 or later; this patch disables the timers before teardown.
  • As a temporary measure, unload or stop the Bluetooth kernel modules (for example by executing rmmod hci or stopping the Bluetooth service) to prevent device teardown until the kernel patch is applied.
  • Enable additional kernel mitigations such as KASLR and page‑fault protection, and monitor the system for related crash logs to detect any remaining memory corruption issues.

Generated by OpenCVE AI on August 22, 2026 at 02:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() hci_unregister_dev() does not disable cmd_timer and ncmd_timer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free. Add disable_delayed_work_sync() calls alongside the existing disable_work_sync() calls to ensure both timers are fully quiesced before teardown proceeds.
Title Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:45:38.299Z

Reserved: 2026-08-15T05:44:03.882Z

Link: CVE-2026-74302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:29.813

Modified: 2026-08-17T06:19:24.323

Link: CVE-2026-74302

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74302 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:45:03Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference