NULL pointer dereference in Linux kernel - CVE-2026-64405
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in hci_abort_conn() when handling connection cancellation from the hci_rx_work() receive path. A local user can trigger a pending Bluetooth connection state to cause a denial of service.
The issue can lead to a general protection fault while a connection request is pending and hdev->sent_cmd is NULL.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64405
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a
- https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348
- https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819
- https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2
- https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0
- https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1