PT-2026-64626 · Linux · Linux
CVE-2026-64405
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci conn: Fix null ptr deref in hci abort conn()
hci abort conn() read hci skb event(hdev->sent cmd) when a connection
was pending, but hdev->sent cmd can be NULL while req status is still
HCI REQ PEND, leading to a NULL pointer dereference and a general
protection fault from the hci rx work() receive path.
Instead of inspecting hdev->sent cmd, track the in-flight create
connection command with a new per-connection HCI CONN CREATE flag and
route all cancellation through hci cancel connect sync(), which
dispatches to a dedicated per-type cancel function. The create command
is in exactly one of two states: still queued, or in flight. The cancel
function holds cmd sync work lock across the whole decision: the worker
takes this lock to dequeue every entry, so while it is held a queued
command cannot start running and an in-flight command cannot complete
and let the next command become pending. This keeps the flag test and
hci cmd sync cancel() atomic with respect to the worker, so a queued
command is simply dequeued, and an in-flight command owned by this
connection is cancelled without the risk of cancelling an unrelated
command that became pending in the meantime. CIS uses the same flag
mechanism via HCI CONN CREATE CIS but cannot be dequeued per-connection.
hci acl create conn sync() and hci le create conn sync() clear
HCI CONN CREATE after the create command completes, but the command
status handler can free conn via hci conn del() (for example when the
controller rejects the connection) while the worker is still blocked on
the connection complete event. Hold a reference on conn across the
create command so the flag can be cleared without a use-after-free.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux