SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74540

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth L2CAP implementation, specifically in the l2cap_le_connect_rsp() function, which is susceptible to a use-after-free condition due to improper reference handling. This flaw can lead to potential remote code execution or system crashes when a channel is freed while still being accessed, posing a risk to systems utilizing Bluetooth connectivity. Organizations that rely on Linux-based systems with Bluetooth capabilities should prioritize addressing this vulnerability to mitigate security risks.

CVE
CVE-2026-74540
Severity
HIGH
CVSS
8.8
EPSS
0.26%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp l2cap_le_connect_rsp() obtains a channel via __l2cap_get_chan_by_ident() but neither holds a reference nor uses l2cap_chan_hold_unless_zero() before locking and operating on it. A concurrent l2cap_chan_del() triggered by a remote disconnect can free the channel between the lookup and l2cap_chan_lock(), causing a use-after-free. The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero() to safely hold a reference, but l2cap_le_connect_rsp() was left unprotected. Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup and l2cap_chan_put() on the exit path, consistent with other L2CAP response handlers.