Use-after-free in Linux kernel - CVE-2026-97908
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the btqcomsmd Bluetooth driver when the command or ACL RPMsg endpoint receives data during device teardown. A remote attacker can trigger delivery of data from WCNSS during device teardown to cause an endpoint callback to dereference an already freed hci_dev.