CVE-2026-93247
Received Received - Intake

NULL Pointer Dereference in Linux Kernel Bluetooth Management

Vulnerability report for CVE-2026-93247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference 'uuid_count' member of struct 'discovery_state' is assigned and read without any locks, so there is a chance of situation when uuid_count != 0, but uuids is NULL and there will be NULL pointer dereference. Possible race: 'hci_update_passive_scan_sync' 'hci_discovery_filter_clear' hdev->discovery.uuid_count = 0; <----------------------preempted-----------------------------> 'start_service_discovery' // Set uuid_count to value != 0 hdev->discovery.uuid_count = uuid_count; hdev->discovery.uuids = kmemdup(...); <----------------------preempted-----------------------------> spin_lock(&hdev->discovery.lock); kfree(hdev->discovery.uuids); hdev->discovery.uuids = NULL; spin_unlock(&hdev->discovery.lock); Now uuids == NULL and uuid_count != 0. So 'mgmt_device_found' -> 'is_filter_match' -> 'eir_has_uuids' receives non consistent discovery state, where NULL dereference of uuids happens. To fix it let's add discovery.lock around every read/write of uuid_count, uuids pair of struct members. It is also important to assign uuid_count value only after success kmemdup() allocation in start_service_discovery(), otherwise uuids is NULL, because kmemdup failed, but uuid_count is already assigned to non zero value. The following panic happens: [ ] ------------[ cut here ]------------ [ ] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ ] Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP [ ] CPU: 0 PID: 15056 Comm: kworker/u9:2 [ ] Workqueue: hci0 hci_rx_work [ ] pstate: 10400009 (nzcV daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ ] pc : eir_has_uuids+0x2d8/0x590 [ ] lr : is_filter_match+0x258/0x320 ... [ ] Call trace: [ ] eir_has_uuids+0x2d8/0x590 [ ] is_filter_match+0x258/0x320 [ ] mgmt_device_found+0x5b0/0xafc [ ] process_adv_report.part.0+0x8c8/0xf14 [ ] hci_le_adv_report_evt+0x338/0x3f0 [ ] hci_le_meta_evt+0x1f0/0x4c8 [ ] hci_event_packet+0x440/0xc9c [ ] hci_rx_work+0x44c/0xaf8 [ ] process_one_work+0x54c/0x103c [ ] worker_thread+0x6c4/0x10c4 [ ] kthread+0x274/0x2ec [ ] ret_from_fork+0x10/0x20 [ ] Code: 14000004 91004021 eb14003f 54000180 (f9400024) [ ] ---[ end trace 0000000000000000 ]---

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a race condition in the Linux kernel's Bluetooth management subsystem. It occurs when the uuid_count and uuids members of the discovery_state struct are accessed without proper locking, leading to a NULL pointer dereference. The issue arises when uuid_count is set to a non-zero value but uuids is NULL due to a failed memory allocation or race during cleanup.

Detection Guidance

This vulnerability is a Linux kernel Bluetooth race condition leading to NULL pointer dereference. Detection requires checking kernel logs for NULL pointer dereference panics related to Bluetooth operations. Monitor system logs for crashes in hci_rx_work or mgmt_device_found functions. No specific commands are provided in the context.

Impact Analysis

This vulnerability can cause a kernel panic (system crash) when Bluetooth device discovery is active. It may lead to denial of service on affected systems, requiring a reboot to restore functionality. Users relying on Bluetooth for critical operations could experience unexpected system failures.

Compliance Impact

This vulnerability is a NULL pointer dereference in the Linux kernel's Bluetooth management subsystem. It does not directly relate to data privacy, access control, or audit logging requirements in GDPR or HIPAA. The impact is limited to potential kernel crashes in systems using affected Bluetooth functionality, which could lead to denial of service but does not inherently violate compliance standards.

Mitigation Strategies

Apply the Linux kernel patch that adds discovery.lock around uuid_count and uuids operations. Update to a kernel version containing the fix. If immediate patching is not possible, disable Bluetooth discovery features as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93247. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart