CVE-2026-53073: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to NULL. This means incoming UART data will reach the protocol-specific recv handler in hci_uart_tty_receive() after resources are freed. Clear HCI_UART_PROTO_INIT with a write lock before calling hu->proto->close() and setting hu->hdev to NULL. The write lock ensures all active readers have completed and no new reader can enter the protocol recv path before resources are freed. This allows the protocol-specific recv functions to remove the "HCI_UART_REGISTERED" guard without risking a null pointer dereference if hci_register_dev() fails.
Affected products
- Linux Linux Kernel: from 5.4.293, before 5.5 (fixed in 5.5); from 5.10.237, before 5.10.258 (fixed in 5.10.258); from 5.15.181, before 5.15.209 (fixed in 5.15.209); from 6.1.135, before 6.1.175 (fixed in 6.1.175); from 6.6.88, before 6.6.141 (fixed in 6.6.141); from 6.12.24, before 6.12.91 (fixed in 6.12.91); …
Published 2026-06-24. Last modified 2026-07-21.