cbcvebase.
CVE-2026-46275
published 2026-06-08

CVE-2026-46275: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions were observed in the lifecycle management of hci_uart. The primary issue arises because the workqueues (init_ready and write_work) are only flushed/cancelled if the HCI_UART_PROTO_READY flag is set during TTY close. If a hangup occurs before setup completes, hci_uart_tty_close() skips the teardown of these workqueues and proceeds to free the `hu` struct. When the scheduled work executes later, it blindly dereferences the freed `hu` struct. Furthermore, several data races and UAFs were identified in the teardown sequence: 1. Calling hci_uart_flush() from hci_uart_close() without effectively disabling write_work causes a race condition where both can concurrently double-free hu->tx_skb. This happens because protocol timers can concurrently invoke hci_uart_tx_wakeup() and requeue write_work. 2. Calling hci_free_dev(hdev) before hu->proto->close(hu) causes a UAF when vendor specific protocol close callbacks dereference hu->hdev. 3. In the initialization error paths, failing to take the proto_lock write lock before clearing PROTO_READY leads to races with active readers. Additionally, hci_uart_tty_receive() accesses hu->hdev outside the read lock, leading to UAFs if the initialization error path frees hdev concurrently. Fix these synchronization and lifecycle issues by: 1. Re-ordering hci_uart_tty_close() to clear HCI_UART_PROTO_READY first, followed immediately by a cancel_work_sync(&hu->write_work). Clearing the flag locks out concurrent protocol timers from successfully invoking hci_uart_tx_wakeup(), effectively rendering the cancellation permanent and preventing the tx_skb double-free. 2. Note: Clearing PROTO_READY early causes hci_uart_close() to skip hu->proto->flush(). This is perfectly safe in the tty_close path because hu->pr

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < 78aad93e938f013d9272fe0ee168f27883afa95c78aad93e938f013d9272fe0ee168f27883afa95c
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < e2d19969c8d9198ecc3090bcd5312ecd503a3339e2d19969c8d9198ecc3090bcd5312ecd503a3339
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < c85cff648a2bc92322912db5f1727ad05afae7b6c85cff648a2bc92322912db5f1727ad05afae7b6
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < 9d20d48be2c4a071fb015eb09bda2cecd25daf349d20d48be2c4a071fb015eb09bda2cecd25daf34
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < 81c7a3c22a0f2808cf4ae0b4908f59763b23606d81c7a3c22a0f2808cf4ae0b4908f59763b23606d
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < 192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < 7338031946bd06f6dff149e67b60c4cd083bfea87338031946bd06f6dff149e67b60c4cd083bfea8
linuxlinux>= 3b799254cf6f481460719023d7a18f46651e5e7f < c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429bc1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b
linuxlinux>= 4.14.203 < 4.154.15
linuxlinux>= 4.19.153 < 4.204.20
linuxlinux>= 5.4.73 < 5.55.5
linuxlinux>= 5.8.17 < 5.95.9
linuxlinux>= 5.9.2 < 5.105.10
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.14.203 < 4.154.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.