8.8
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
hci_conn lookup and field access must be covered by hdev lock in
hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise
the connection can be freed concurrently.
Extend the hci_dev_lock critical section to cover all conn usage in both
handlers.
Keep the existing keypress notification behavior unchanged by routing
the early exits through a common unlock path.
Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
hci_conn lookup and field access must be covered by hdev lock in
hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise
the connection can be freed concurrently.
Extend the hci_dev_lock critical section to cover all conn usage in both
handlers.
Keep the existing keypress notification behavior unchanged by routing
the early exits through a common unlock path.
Basic Information
ID
CVE-2026-46056
Source
Linux
Published
May 27, 2026 at 12:57
Modified
May 30, 2026 at 10:47
Affected Product
Vendor
Linux
Product
Linux
Version
92a25256f142d55e25f9959441cea6ddeabae57e
Affected Versions
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 3.7
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 92a25256f142d55e25f9959441cea6ddeabae57e
Linux Linux 3.7
References
- git.kernel.org /stable/c/204028af77a265e31ceb4ba7f643349a3cca72b2
- git.kernel.org /stable/c/01a6431766c35dfedb86e0cb5d3fc80c6d604a47
- git.kernel.org /stable/c/e08d75753db17aa943d7622f09d9c217b5bfd3b8
- git.kernel.org /stable/c/8c6443bb9257b780986fb67ec08565bf48ecb8d7
- git.kernel.org /stable/c/85fa3512048793076eef658f66489112dcc91993