Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device

hu->serdev is NULL for hci_uart attached via non-serdev paths, but
qca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev)
and dereferences the result, causing a NULL pointer dereference.

Fix by guarding the dereference with a NULL check, consistent with the
rest of qca_setup().
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference in the hci_qca driver’s qca_setup() function allows a crash when a Bluetooth controller is attached via a non-serdev path. The crash occurs because the code attempts to obtain driver data from a null "serdev" object and dereferences the result, leading to a kernel panic and nearby system reboot. This yields a loss of availability of the affected system and any services that depend on it.

Affected Systems

The flaw exists in any Linux kernel that includes the unpatched hci_qca driver. Because the issue arises prior to the commit that added the null-check release, any kernel built with that driver before the update is potentially vulnerable. The vendor in question is Linux and the kernel itself is the affected product.

Risk and Exploitability

The vulnerability has a CVSS score of 5.5 and is not present in the CISA KEV catalog, but the EPSS score indicates a very low but non-zero exploitation probability (less than 1%). Based on the description, it is inferred that the attack vector is local or physical, requiring an attacker to have direct access to the target system to trigger qca_setup() through a non-serdev Bluetooth device. If an attacker can supply or connect such a device, the kernel crash can be forced, causing a denial of service. No remote exploitation path is documented, yet the local impact remains high due to the kernel panic.

Generated by OpenCVE AI on August 22, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the NULL check fix for the hci_qca driver
  • Disable or unload the hci_qca module if the Bluetooth hardware is not required
  • If an update cannot be applied immediately, disable Bluetooth or remove non-serdev Bluetooth devices to prevent the crash from occurring

Generated by OpenCVE AI on August 22, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-758

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device hu->serdev is NULL for hci_uart attached via non-serdev paths, but qca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev) and dereferences the result, causing a NULL pointer dereference. Fix by guarding the dereference with a NULL check, consistent with the rest of qca_setup().
Title Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:16:51.786Z

Reserved: 2026-08-15T05:44:03.882Z

Link: CVE-2026-74304

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:30.037

Modified: 2026-08-17T06:19:24.570

Link: CVE-2026-74304

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74304 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T00:45:05Z

Weaknesses
  • CWE-476

    NULL Pointer Dereference

  • CWE-758

    Reliance on Undefined, Unspecified, or Implementation-Defined Behavior