Bluetooth Functionality Vulnerability in Linux Kernel
CVE-2026-68393
What is CVE-2026-68393?
A vulnerability in the Bluetooth protocol stack of the Linux kernel allows improper handling of RCU-protected pointers outside critical sections. This can lead to user-after-free conditions if the connection hash is concurrently modified while in use. The issue is mitigated by extending critical sections to encompass hash lookups and ensuring that device locks are properly managed during access to connection-related data. Proper handling of reference counts and critical section management is essential to avoid potential exploits.
Affected Version(s)
Linux 6d0417e4e1cf66fd917f06f0454958362714ef7d < 83b7e67698d0b93f685875ce82c8d335436834f7
Linux 6d0417e4e1cf66fd917f06f0454958362714ef7d < 38326774df6198df0cc2744cc73bf77cb741c538
Linux 6d0417e4e1cf66fd917f06f0454958362714ef7d