Use-after-free in Linux kernel - CVE-2026-89569
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to access freed RFCOMM session and data link connection objects.
The vulnerability exists due to use-after-free in the RFCOMM security confirmation handler rfcomm_security_cfm() when processing Bluetooth security confirmations concurrently with RFCOMM session teardown. A remote attacker can trigger the concurrent processing to access freed RFCOMM session and data link connection objects.