{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74302","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.882Z","datePublished":"2026-08-15T05:58:04.638Z","dateUpdated":"2026-08-17T05:45:38.299Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:45:38.299Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix UAF in hci_unregister_dev()\n\nhci_unregister_dev() does not disable cmd_timer and ncmd_timer\nbefore the hci_dev structure is freed. If a timeout fires\nduring device teardown, the callback dereferences freed memory\n(including the hdev->reset function pointer), leading to a\nuse-after-free.\n\nAdd disable_delayed_work_sync() calls alongside the existing\ndisable_work_sync() calls to ensure both timers are fully\nquiesced before teardown proceeds."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached only during hci_unregister_dev() teardown (e.g. closing /dev/vhci, USB/btusb disconnect, hci_ldisc detach, or driver removal); adjacent Bluetooth peers can arm cmd_timer/ncmd_timer via HCI timeouts but cannot invoke unregister, so exploitation requires local device/syscall access.\nAC:L - An attacker controls both sides of the race—arming cmd_timer (2s) or ncmd_timer (4s) by withholding HCI command completions while closing /dev/vhci to run hci_unregister_dev(), and disable_work_sync(cmd_work) can queue cmd_timer immediately before teardown; the cycle is repeatable.\nPR:L - vhci_open() has no capable() check, so any principal granted /dev/vhci (syzkaller, containers, Android bluetooth uid, permissive udev) can create/destroy virtual HCI controllers and inject frames without init-namespace root, matching prior hci_unregister_dev teardown UAF scores.\nUI:N - The attacker performs device creation, HCI traffic injection, and teardown from its own process via open/write/close on /dev/vhci or equivalent local transport; no victim interaction or cooperation is required beyond existing device-node access.\nS:U - Corruption is confined to kernel slab memory and workqueue/timer state within the same kernel security authority; exploitation yields standard kernel privilege escalation, not VM escape, IOMMU bypass, or cross-sandbox boundary crossing.\nC:H - hci_cmd_timeout() and hci_ncmd_timeout() dereference the freed hci_dev (req_skb, flags, workqueue, name) after kfree(); UAF on the hci_dev slab enables controlled reallocation and arbitrary kernel memory read/pointer disclosure via heap spraying.\nI:H - hci_cmd_timeout() invokes the freed hdev->reset function pointer and re-queues cmd_work on hdev->workqueue; attacker-controlled contents in the reclaimed hci_dev object provide arbitrary write and control-flow hijack primitives per kernel UAF scoring guidance.\nA:H - Timer callbacks operating on freed hci_dev memory cause KASAN slab-use-after-free reports, kernel oops/panic, and can queue work onto destroyed workqueues; even failed exploitation reliably crashes or hangs the affected controller path."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hci_core.c"],"versions":[{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"48c7ad6afcc58c2cda11fed39791708103b6a644","status":"affected","versionType":"git"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"a0fd1086a57b982f8c24ae4ab165c2af39fe1735","status":"affected","versionType":"git"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"672d52d9412252e61b8de8d773ccdf5a277cf540","status":"affected","versionType":"git"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"5edcc018fa6e80b2c478454a4a8229c23d67c181","status":"affected","versionType":"git"},{"version":"48542881997e17b49dc16b93fe910e0cfcf7a9f9","status":"affected","versionType":"git"},{"version":"9cfc84b1d464cc024286f42a090718f9067b80ed","status":"affected","versionType":"git"},{"version":"ddeda6ca5f218b668b560d90fc31ae469adbfd92","status":"affected","versionType":"git"},{"version":"d2ce562a5aff1dcd0c50d9808ea825ef90da909f","status":"affected","versionType":"git"},{"version":"96600c2e5ee8213dbab5df1617293d8e847bb4fa","status":"affected","versionType":"git"},{"version":"d6cbce18370641a21dd889e8613d8153df15eb39","status":"affected","versionType":"git"},{"version":"3f939bd73fed12dddc2a32a76116c19ca47c7678","status":"affected","versionType":"git"},{"version":"4.19.319","lessThan":"4.20","status":"affected","versionType":"semver"},{"version":"5.4.281","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.10.223","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.15.164","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"6.1.101","lessThan":"6.2","status":"affected","versionType":"semver"},{"version":"6.6.42","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.9.11","lessThan":"6.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hci_core.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.319"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.281"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.223"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.164"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/48c7ad6afcc58c2cda11fed39791708103b6a644"},{"url":"https://git.kernel.org/stable/c/a0fd1086a57b982f8c24ae4ab165c2af39fe1735"},{"url":"https://git.kernel.org/stable/c/672d52d9412252e61b8de8d773ccdf5a277cf540"},{"url":"https://git.kernel.org/stable/c/5edcc018fa6e80b2c478454a4a8229c23d67c181"}],"title":"Bluetooth: hci_core: Fix UAF in hci_unregister_dev()","x_generator":{"engine":"bippy-1.2.0"}}}}