CVE-2026-98295
Received
Received - Intake
Bluetooth Use-After-Free in Linux Kernel
Vulnerability report for CVE-2026-98295, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: coredump: Quiesce dump work on unregister
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.
Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 9695ef876fd122cb7bbc04a4a93b8727d2e36bda |
| Linux | Linux | 9695ef876fd122cb7bbc04a4a93b8727d2e36bda |
| Linux | Linux | 9695ef876fd122cb7bbc04a4a93b8727d2e36bda |
| Linux | Linux | 9695ef876fd122cb7bbc04a4a93b8727d2e36bda |
| Linux | Linux | deb8156ebe5cb63a5988e7f86cc46aa062527c2b |
| Linux | Linux | 6.1.188 |
| Linux | Linux | 6.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |