SB2026072788 - Use-after-free in Linux kernel bluetooth driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64470)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to use-after-free in the btusb probe path in drivers/bluetooth/btusb.c when handling probe failures after Marvell OOB wakeup configuration. A local user can trigger a device probe failure after TX URBs have been submitted to cause a use-after-free.
The issue occurs in the completion callback for submitted TX URBs.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4
- https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed
- https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8
- https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af
- https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a
- https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e
- https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2
- https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79