Use-after-free in Linux kernel - CVE-2026-74531
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in abort_conn_sync() in net/bluetooth/hci_conn.c when handling Bluetooth connection abort operations. A local user can trigger a connection abort race to cause a denial of service.
The issue is theoretical and occurs if the connection object is freed while the hci_sync task is running.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74531
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/5761d003daa987ac81463f570713ce9c9dd204e5
- https://git.kernel.org/stable/c/64d1645f26aa49b5a86ba2fccd0bb6749ea725a6
- https://git.kernel.org/stable/c/963fb4b8e7d1ab07b4ae45bf15d41e667c88caca
- https://git.kernel.org/stable/c/e8f9fef362bab431d95371d3406bc720350290c3
- https://git.kernel.org/stable/c/fa812cfa81aa3d4a7b6ce8277979af57b3f79712