CVE-2026-74302: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() hci_unregister_dev() does not disable cmd_timer and ncmd_timer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free. Add disable_delayed_work_sync() calls alongside the existing disable_work_sync() calls to ensure both timers are fully quiesced before teardown proceeds.

Affected products

  • Linux Linux: from 4.19.319, before 4.20 (fixed in 4.20); from 5.4.281, before 5.5 (fixed in 5.5); from 5.10.223, before 5.11 (fixed in 5.11); from 5.15.164, before 5.16 (fixed in 5.16); from 6.1.101, before 6.2 (fixed in 6.2); from 6.6.42, before 6.7 (fixed in 6.7); …

Published 2026-08-15. Last modified 2026-08-17.