SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64406

HIGH · CVSS 8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Linux kernel's Bluetooth subsystem can lead to memory access violations during the cleanup of listening L2CAP sockets, potentially allowing an attacker to execute arbitrary code or crash the system. This high-severity issue primarily affects Linux distributions that utilize the Bluetooth stack and should be prioritized by system administrators and developers maintaining Bluetooth-enabled devices or applications. Immediate patching is recommended to mitigate the risk of exploitation.

CVE
CVE-2026-64406
Severity
HIGH
CVSS
8
EPSS
0.27%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.