CVE-2026-64406: Linux Kernel

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.

Affected products

  • Linux Linux Kernel: from 5.10.259, before 5.10.261 (fixed in 5.10.261); from 5.15.210, before 5.15.212 (fixed in 5.15.212); from 6.1.175, before 6.1.178 (fixed in 6.1.178); from 6.6.142, before 6.6.145 (fixed in 6.6.145); from 6.12.92, before 6.12.96 (fixed in 6.12.96); from 6.18.34, before 6.18.39 (fixed in 6.18.39); …

Published 2026-07-25. Last modified 2026-09-04.