SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74529

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's Bluetooth subsystem could lead to a theoretical use-after-free (UAF) condition if a connection is freed while the hci_sync task is executing. This could potentially allow an attacker to exploit the flaw, impacting systems that rely on Bluetooth functionality. Organizations using Linux-based systems with Bluetooth capabilities should prioritize applying updates to mitigate this risk.

CVE
CVE-2026-74529
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.