Bluetooth Management Locking Flaw in Linux Kernel
CVE-2026-68392

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68392?

The Linux kernel is affected by a vulnerability involving improper locking mechanisms in the Bluetooth management subsystem. Specifically, the flaw arises from dereferencing pointers protected by RCU outside of critical sections, leading to potential use-after-free (UAF) scenarios. This vulnerability can compromise the integrity and security of Linux systems by allowing unauthorized access to memory that should be protected. Resolutions have been implemented to ensure that connection lookups and aborts use the appropriate locking mechanisms to prevent premature dereferencing.

Affected Version(s)

Linux 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c < 8bc83f9ef6789571f399ff631a2a14a12b6d8585

Linux 227a0cdf4a028a73dc256d0f5144b4808d718893 < 579faba5ede6df6b7f36777c431dc8dcf9d272e7

Linux 227a0cdf4a028a73dc256d0f5144b4808d718893

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.