cbcvebase.
CVE-2026-23462
published 2026-04-03

CVE-2026-23462: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping…

PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.26%
17.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping l2cap_conn reference when user->remove callback is called: [ 97.809249] l2cap_conn_free: freeing conn ffff88810a171c00 [ 97.809907] CPU: 1 UID: 0 PID: 1419 Comm: repro_standalon Not tainted 7.0.0-rc1-dirty #14 PREEMPT(lazy) [ 97.809935] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 [ 97.809947] Call Trace: [ 97.809954] [ 97.809961] dump_stack_lvl (lib/dump_stack.c:122) [ 97.809990] l2cap_conn_free (net/bluetooth/l2cap_core.c:1808) [ 97.810017] l2cap_conn_del (./include/linux/kref.h:66 net/bluetooth/l2cap_core.c:1821 net/bluetooth/l2cap_core.c:1798) [ 97.810055] l2cap_disconn_cfm (net/bluetooth/l2cap_core.c:7347 (discriminator 1) net/bluetooth/l2cap_core.c:7340 (discriminator 1)) [ 97.810086] ? __pfx_l2cap_disconn_cfm (net/bluetooth/l2cap_core.c:7341) [ 97.810117] hci_conn_hash_flush (./include/net/bluetooth/hci_core.h:2152 (discriminator 2) net/bluetooth/hci_conn.c:2644 (discriminator 2)) [ 97.810148] hci_dev_close_sync (net/bluetooth/hci_sync.c:5360) [ 97.810180] ? __pfx_hci_dev_close_sync (net/bluetooth/hci_sync.c:5285) [ 97.810212] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 97.810242] ? up_write (./arch/x86/include/asm/atomic64_64.h:87 (discriminator 5) ./include/linux/atomic/atomic-arch-fallback.h:2852 (discriminator 5) ./include/linux/atomic/atomic-long.h:268 (discriminator 5) ./include/linux/atomic/atomic-instrumented.h:3391 (discriminator 5) kernel/locking/rwsem.c:1385 (discriminator 5) kernel/locking/rwsem.c:1643 (discriminator 5)) [ 97.810267] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 97.810290] ? rcu_is_watching (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/context_tracking.h:128 kernel/rcu/tree.c:752) [ 97.810320] hci_unregister_dev (net/bluetooth/hci_core.c:504 ne

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < d955ccbf91ab74d76fe9e4eab2846a7d8a173075d955ccbf91ab74d76fe9e4eab2846a7d8a173075
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < 18b1263ece6431bd78fa6b61faaef5281203741c18b1263ece6431bd78fa6b61faaef5281203741c
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < 21a47a119f33df9bb157326846390d7e8e1b45ba21a47a119f33df9bb157326846390d7e8e1b45ba
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < 45ebe5b900200ac3e01f3470506a44a44782572145ebe5b900200ac3e01f3470506a44a447825721
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < 7c805b7d1e580eececcc92470292e3dbc42bc3f57c805b7d1e580eececcc92470292e3dbc42bc3f5
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < f8b6ed2f06d3baa44f347a0fa2af52433f386463f8b6ed2f06d3baa44f347a0fa2af52433f386463
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < 4d37fa7582aa960ba23e10a7a2596a29f37ad2814d37fa7582aa960ba23e10a7a2596a29f37ad281
linuxlinux>= b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 < dbf666e4fc9bdd975a61bf682b3f75cb0145eedddbf666e4fc9bdd975a61bf682b3f75cb0145eedd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 3.10 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.