Use-After-Free Vulnerability in Linux Kernel Bluetooth Module
CVE-2026-80692
Currently unrated
What is CVE-2026-80692?
A use-after-free vulnerability has been identified in the Bluetooth module of the Linux Kernel. This arises when a connection object is freed while the hci_sync task is still operational, leading to potential security risks. The issue can be mitigated by maintaining a reference count to the connection during the execution of the hci_connect_acl/le_sync callbacks, ensuring safer memory management and stability in Bluetooth operations.
Affected Version(s)
Linux 881559af5f5c545f6828e7c74d79813eb886d523 < 9a77f296aff4b2ca5f2928ab3a3220c82d8b4074
Linux 881559af5f5c545f6828e7c74d79813eb886d523 < 2f5d635ad5906b0235bc0c870e8beba3116e1e98
Linux d948e1ffa1d40240d5c81af6dcbcb87b39cb8d3c