CVE-2026-98294
Received Received - Intake

Bluetooth Use-After-Free in Linux Kernel Bluetooth Stack

Vulnerability report for CVE-2026-98294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Do not write to the serial port after it is closed hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP is set (for example, for the WCN399x family). A failed hci_dev_open_sync() following a successful qca_setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs_on is left true. qca_serdev_remove() then passes its power->vregs_on test and calls qca_power_off(), which writes to the closed port unconditionally. Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca_power_off() was still named qca_power_shutdown(): Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: tty_set_termios+0x50/0x238 (P) ttyport_set_baudrate+0x84/0xc0 serdev_device_set_baudrate+0x24/0x40 qca_power_shutdown+0x158/0x1fc [hci_uart] qca_serdev_remove+0x54/0x68 [hci_uart] serdev_drv_remove+0x1c/0x2c device_remove+0x4c/0x80 device_release_driver_internal+0x1cc/0x224 device_driver_detach+0x18/0x24 unbind_store+0xb4/0xc0 Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down. The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Linux Linux fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3
Linux Linux fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3
Linux Linux fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3
Linux Linux 4.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a Bluetooth driver (hci_qca) that writes to a serial port after it has been closed. When the port is closed due to a failed device open operation, the driver's cleanup function (qca_power_off) still attempts to write to the closed port, leading to a kernel crash or use-after-free issue.

Detection Guidance

This vulnerability is specific to the Linux kernel's Bluetooth subsystem and may not have direct network detection methods. Monitor kernel logs for errors related to Bluetooth driver crashes or NULL pointer dereferences during driver unbind operations. Check for kernel oops or panic messages after unbinding the hci_uart driver.

Impact Analysis

This vulnerability can cause system instability, crashes, or potential privilege escalation if exploited. It may lead to denial-of-service conditions on affected systems using specific Bluetooth hardware (e.g., WCN399x family).

Mitigation Strategies

Apply the latest kernel updates or patches that address this issue. Avoid unbinding the hci_uart driver after a controller failure. If unbinding is necessary, ensure the system is rebooted afterward to reset the Bluetooth controller state.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart