Use of uninitialized resource in Linux kernel - CVE-2026-74508
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in hidp_recv_ctrl_frame() and hidp_recv_intr_frame() in the HIDP subsystem when processing crafted Bluetooth HIDP frames without a transaction header. A remote user can send a specially crafted empty or malformed frame to cause a denial of service.
The issue can terminate the HIDP session when a malformed lower-layer packet causes an extra byte to be consumed as a virtual cable unplug control value.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74508
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96
- https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec
- https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf
- https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d
- https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811