CVE-2026-64406

Updated on 25 Jul 2026

Severity

Awaiting Analysis

Details

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: fix UAF in bt_accept_dequeue()

bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference.

bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup.

Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.

Details

Affected product:
Debian 11 ELS
Affected packages:
linux @ 5.10.259

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 11 In Rollout
1 kernel
  • 5.10.259-1
Debian 11 cloud Released
1 kernel
  • 5.10.259-1
Debian 12 Planned
Oracle Linux 9 UEK 7 Planned