In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls
hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm()
assumes it is held, and if conn is deleted concurrently -> UAF.
Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen,
and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred
listening socket code paths, hci_connect_cfm(conn) is called with
hdev->lock held.
Fix by holding the lock.
References
Configurations
Configuration 1 (hide)
|
History
21 Jul 2026, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-667 | |
| References | () https://git.kernel.org/stable/c/385b2d0468a0871fc716c549fa3b0c257c7dbcb3 - Patch | |
| References | () https://git.kernel.org/stable/c/541d5bf9b5afaf41090b2a3aa7b47f2db2ff801f - Patch | |
| References | () https://git.kernel.org/stable/c/5c7209a341ff2ac338b2b0375c34a307b37c9ac2 - Patch | |
| References | () https://git.kernel.org/stable/c/60e3f4ff02d1f2d55bfbf2ca32a97285a9771ee4 - Patch | |
| References | () https://git.kernel.org/stable/c/6b4d226d01ab7da0d2027a2a1e3a6079152e5065 - Patch | |
| References | () https://git.kernel.org/stable/c/9d4a6c0f43fc5e4d4f062e8e450e5483eb74176e - Patch | |
| References | () https://git.kernel.org/stable/c/c27224daf0b08efbb2b24ed64b6139b294f5473a - Patch | |
| References | () https://git.kernel.org/stable/c/c7777f534a8018ae4bb1c80d8925af4df588a314 - Patch | |
| First Time |
Linux linux Kernel
Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
28 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
24 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 17:17
Updated : 2026-07-21 17:40
NVD link : CVE-2026-53072
Mitre link : CVE-2026-53072
CVE.ORG link : CVE-2026-53072
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-667
Improper Locking
