IT

Tracker / CVE-2026-53072

CVE-2026-53072

High 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assumes it is held, and if conn is deleted concurrently -> UAF. Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen, and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred listening socket code paths, hci_connect_cfm(conn) is called with hdev->lock held. Fix by holding the lock.

Affected products and versions

linux linux_kernel · 3.17 → 5.10.258
linux linux_kernel · 5.11 → 5.15.209
linux linux_kernel · 5.16 → 6.1.175
linux linux_kernel · 6.13 → 6.18.33
linux linux_kernel · 6.19 → 7.0.10
linux linux_kernel · 6.2 → 6.6.141
linux linux_kernel · 6.7 → 6.12.91

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References