CVE-2026-97977
Użycie poświadczeń w Bluetooth w jądrze Linuxa prowadzi do wykorzystania po zwolnieniu pamięci.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix UAF of btusb_data by rx_work btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns. btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data: while ((skb = skb_dequeue(&data->acl_q))) data->recv_acl(data->hdev, skb); Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-25 11:17:25 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:18:21 UTC |
- https://git.kernel.org/stable/c/1c12c3117639e78940959d956519c758c57d0849 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/472d005622525b7be155cac99dde2252b0163bd1 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/5242050195a711e9cd6a9935f689ab6656b94a91 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/93b59937bda3fffc6386c79f5544a39bc680c8e8 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fa391adb9c755515a89993634745e9079e5ef37c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fc654a72a8d979db15e2773a481e931abaf5a9e8 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)