Use-after-free in Linux kernel - CVE-2026-64406
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in bt_accept_dequeue() when handling Bluetooth L2CAP socket cleanup and accept queue processing. A local user can trigger socket state transitions that cause freed memory to be accessed to cause a denial of service.
The issue was observed during listening L2CAP socket cleanup.
Affected software
How to mitigate CVE-2026-64406
External References
- https://git.kernel.org/stable/c/0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0
- https://git.kernel.org/stable/c/26168db1ce5a9766cde021b18e590a101c056614
- https://git.kernel.org/stable/c/4bd0b274054f2679f28b70222b607bb0afc3ab9a
- https://git.kernel.org/stable/c/50c662bdcd51b03033a0abed6716bfd377ba1049
- https://git.kernel.org/stable/c/6303ed4bbe0095f4cc195225479bf506e010d1db
- https://git.kernel.org/stable/c/96ad400d5132eb333f28f6f1e2d58f0728ca9547
- https://git.kernel.org/stable/c/c0577c55219be42b6ea2ea8db11e85bfab6f4e8d
- https://git.kernel.org/stable/c/c66a95e60b65d876a927123b0ed36bd6177d9ca6