Bluetooth Vulnerability in Linux Kernel Affects Multiple Releases
CVE-2026-63974

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63974?

A vulnerability within the Linux kernel impacts Bluetooth device management. Specifically, the handling of device closure during the reset path has been modified to ensure that the HCI_CMD_DRAIN_WORKQUEUE command is set when the hci_dev_close_sync() function is invoked. This adjustment is crucial in preventing potential queuing timeouts while draining the hdev workqueue, contributing to improved stability and performance when managing Bluetooth devices.

Affected Version(s)

Linux 877afadad2dce8aae1f2aad8ce47e072d4f6165e < 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9

Linux 877afadad2dce8aae1f2aad8ce47e072d4f6165e < 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e

Linux 877afadad2dce8aae1f2aad8ce47e072d4f6165e < 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.