Use-after-free in Linux kernel - CVE-2026-64470
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to use-after-free in the btusb probe path in drivers/bluetooth/btusb.c when handling probe failures after Marvell OOB wakeup configuration. A local user can trigger a device probe failure after TX URBs have been submitted to cause a use-after-free.
The issue occurs in the completion callback for submitted TX URBs.
Affected software
How to mitigate CVE-2026-64470
External References
- https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4
- https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed
- https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8
- https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af
- https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a
- https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e
- https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2
- https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79