Use-after-free Vulnerability in Linux Kernel Bluetooth L2CAP Module
CVE-2026-74540
What is CVE-2026-74540?
A use-after-free vulnerability in the Bluetooth L2CAP module of the Linux Kernel could be exploited due to a mishandling of references during connection response handling. The l2cap_le_connect_rsp() function fails to maintain a reference to a channel after retrieval, allowing a concurrent deletion operation to free the channel unexpectedly. This flaw may lead to potential crashes or arbitrary code execution if exploited by an attacker, emphasizing the necessity for proper reference management in code handling critical communication protocols.
Affected Version(s)
Linux f1496dee9cbde2a62821f4441dadb0d3360f60c3
Linux f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 522b730c62c53a1981604fd73524697fd347830d
Linux f1496dee9cbde2a62821f4441dadb0d3360f60c3 < 58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136