CVE-2026-46275
published 2026-06-08CVE-2026-46275: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer
Dereference (NPD) conditions were observed in the lifecycle management
of hci_uart.
The primary issue arises because the workqueues (init_ready and
write_work) are only flushed/cancelled if the HCI_UART_PROTO_READY
flag is set during TTY close. If a hangup occurs before setup completes,
hci_uart_tty_close() skips the teardown of these workqueues and
proceeds to free the `hu` struct. When the scheduled work executes
later, it blindly dereferences the freed `hu` struct.
Furthermore, several data races and UAFs were identified in the teardown
sequence:
1. Calling hci_uart_flush() from hci_uart_close() without effectively
disabling write_work causes a race condition where both can concurrently
double-free hu->tx_skb. This happens because protocol timers can
concurrently invoke hci_uart_tx_wakeup() and requeue write_work.
2. Calling hci_free_dev(hdev) before hu->proto->close(hu) causes a UAF
when vendor specific protocol close callbacks dereference hu->hdev.
3. In the initialization error paths, failing to take the proto_lock
write lock before clearing PROTO_READY leads to races with active
readers. Additionally, hci_uart_tty_receive() accesses hu->hdev
outside the read lock, leading to UAFs if the initialization error
path frees hdev concurrently.
Fix these synchronization and lifecycle issues by:
1. Re-ordering hci_uart_tty_close() to clear HCI_UART_PROTO_READY first,
followed immediately by a cancel_work_sync(&hu->write_work). Clearing
the flag locks out concurrent protocol timers from successfully invoking
hci_uart_tx_wakeup(), effectively rendering the cancellation permanent
and preventing the tx_skb double-free.
2. Note: Clearing PROTO_READY early causes hci_uart_close() to skip
hu->proto->flush(). This is perfectly safe in the tty_close path
because hu->pr
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < 78aad93e938f013d9272fe0ee168f27883afa95c | 78aad93e938f013d9272fe0ee168f27883afa95c |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < e2d19969c8d9198ecc3090bcd5312ecd503a3339 | e2d19969c8d9198ecc3090bcd5312ecd503a3339 |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < c85cff648a2bc92322912db5f1727ad05afae7b6 | c85cff648a2bc92322912db5f1727ad05afae7b6 |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < 9d20d48be2c4a071fb015eb09bda2cecd25daf34 | 9d20d48be2c4a071fb015eb09bda2cecd25daf34 |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < 81c7a3c22a0f2808cf4ae0b4908f59763b23606d | 81c7a3c22a0f2808cf4ae0b4908f59763b23606d |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < 192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894 | 192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894 |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < 7338031946bd06f6dff149e67b60c4cd083bfea8 | 7338031946bd06f6dff149e67b60c4cd083bfea8 |
| linux | linux | >= 3b799254cf6f481460719023d7a18f46651e5e7f < c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b | c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b |
| linux | linux | >= 4.14.203 < 4.15 | 4.15 |
| linux | linux | >= 4.19.153 < 4.20 | 4.20 |
| linux | linux | >= 5.4.73 < 5.5 | 5.5 |
| linux | linux | >= 5.8.17 < 5.9 | 5.9 |
| linux | linux | >= 5.9.2 < 5.10 | 5.10 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.14.203 < 4.15 | 4.15 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46108 [HIGH] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD D
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TC
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46113 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD Distrib
Red Hat
kernel: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
vendor_redhat·2026-06-08·CVSS 7.0
CVE-2026-46275 [MEDIUM] CWE-476 kernel: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
kernel: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
A flaw was found in the Linux kernel's Bluetooth hci_uart component. Lifecycle management issues, including Use-After-Free (UAF) and race conditions, were identified during the closing and initialization paths. These issues can lead to the dereferencing of freed memory, potentially causing system instability, crashes, or arbitrary code execution.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
GHSA
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null
ghsa_unreviewed·2026-06-08
CVE-2026-46275 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer
Dereference (NPD) conditions were observed in the lifecycle management
of hci_uart.
The primary issue arises because the workqueues (init_ready and
write_work) are only flushed/cancelled if the HCI_UART_PROTO_READY
flag is set during TTY close. If a hangup occurs before setup completes,
hci_uart_tty_close() skips the teardown of these workqueues and
proceeds to free the `hu` struct. When the scheduled work executes
later, it blindly dereferences the freed `hu` struct.
Furthermore, several data races and UAFs were identified in the teardown
sequence:
1. Calling hci_uart_flush() from
VulDB
Linux Kernel up to 7.1-rc4 Bluetooth hci_uart_tty_close tx_skb use after free (Nessus ID 319698)
vuldb·2026-06-08
CVE-2026-46275 [CRITICAL] Linux Kernel up to 7.1-rc4 Bluetooth hci_uart_tty_close tx_skb use after free (Nessus ID 319698)
A vulnerability was found in Linux Kernel up to 7.1-rc4. It has been declared as critical. Affected is the function hci_uart_tty_close of the component Bluetooth. Executing a manipulation of the argument tx_skb can lead to use after free.
The identification of this vulnerability is CVE-2026-46275. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894https://git.kernel.org/stable/c/7338031946bd06f6dff149e67b60c4cd083bfea8https://git.kernel.org/stable/c/78aad93e938f013d9272fe0ee168f27883afa95chttps://git.kernel.org/stable/c/81c7a3c22a0f2808cf4ae0b4908f59763b23606dhttps://git.kernel.org/stable/c/9d20d48be2c4a071fb015eb09bda2cecd25daf34https://git.kernel.org/stable/c/c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429bhttps://git.kernel.org/stable/c/c85cff648a2bc92322912db5f1727ad05afae7b6https://git.kernel.org/stable/c/e2d19969c8d9198ecc3090bcd5312ecd503a3339
2026-06-08
Published