Impact
In the Linux kernel, a concurrency flaw in the Bluetooth HCI synchronization path allows a use‑after‑free if a connection is released while the asynchronous hci_sync task is still running. The defect is triggered from the hci_connect_big_sync() callback where the connection reference is not held. The fix introduces a reference counter guard and safely handles a null connection, matching the previous behavior. This flaw can lead to kernel memory corruption and, in a successful exploitation scenario, arbitrary code execution as root.
Affected Systems
The issue affects all publicly released Linux kernel images that do not contain the patch committed early in 2026. All kernels maintained by the Linux Foundation and derivative distributions are impacted until updated, as no specific version numbers are listed in the advisory.
Risk and Exploitability
The vulnerability has an EPSS score of < 1% and is not listed in the CISA KEV catalog, suggesting no widespread exploitation has yet been observed. The defect is kernel‑level and can be triggered via a Bluetooth connection, giving the attacker a potential remote attack vector that does not require local privileges. Because the flaw is theoretical and requires specific timing conditions, exploitation is considered difficult but not impossible. The CVSS score is 8.8, indicating a high severity risk that could lead to kernel memory corruption and potential privilege escalation.
OpenCVE Enrichment