Race condition in Linux kernel - CVE-2026-97975
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in hci_conn_del_sysfs() and device_del() when concurrently unregistering child devices while connection devices are being removed. A local user can trigger concurrent child device unregistration to cause a NULL pointer dereference.