Use-after-free in Linux kernel - CVE-2026-46111
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in create_big_sync/create_big_complete in the Bluetooth hci_conn handling code when processing BIG creation completion after an asynchronous operation on a stale connection. A local attacker can trigger BIG creation and cause the kernel to dereference a freed connection pointer to cause a denial of service.
How to mitigate CVE-2026-46111
Sources
- https://git.kernel.org/stable/c/0beddb0c380bed5f5b8e61ddbe14635bb73d0b41
- https://git.kernel.org/stable/c/1750a2df0eab61dc421a7afae74abdd239a44b85
- https://git.kernel.org/stable/c/6823f730bf195fc296d9edd09e2ca94bc1ff5584
- https://git.kernel.org/stable/c/dc34f8d8240f25dd137dc2758ebbcc75e3779142
- https://git.kernel.org/stable/c/f8eaf92c57ad99358dd372580d5ff87623343a72