SB20260727158 - Use-after-free in Linux kernel bluetooth



SB20260727158 - Use-after-free in Linux kernel bluetooth

Published: July 27, 2026

Security Bulletin ID SB20260727158
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: N/A)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in hci_le_create_conn_sync() and hci_acl_create_conn_sync() when processing create connection completion handling. A local user can trigger a connection state change that frees conn before flag cleanup to cause a denial of service.

The condition occurs when the command status handler frees the connection object while the worker is still blocked on the connection complete event.


Remediation

Install update from vendor's website.