Linux Kernel

severity

7.8

published

A race in the Linux kernel's Bluetooth MGMT interface can cause add_device_complete() to read an hci_conn_params object after a concurrent device-removal operation has freed it. Triggering the flaw requires high local privileges and a successful race, and can disclose a small amount of kernel memory or crash the system.

add_device_complete() performs an hci_conn_params_lookup() and reads
params->flags without holding hci_dev_lock. A concurrent MGMT_OP_REMOVE_DEVICE operation can remove and free the same object between the lookup and dereference. The fix holds hci_dev_lock across the lookup, flag read, and corresponding event emission. The issue is classified as CWE-416.


References

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

S@tPa1rQt6  lCo2oGkNiTn@gN  aDtN  y6oNuZrN  sDoXfFtDwIa6r2e5  c1rFiVtZiPc#aAl7lGy9.0

request briefing

request briefing

SQt2aBr3tT  lDoSoDk7i5n4g%  a0tR  yLoFu$rP  sMo1fJtYwEaNrVeZ  cUr$iVtTiIc7aHlXlCyK.G

request briefing

request briefing

S0tMa2rUtP  lUoLoRk$iAnGgM  a2t#  yJoZuUrZ  s1oXfDtNw5aBrQeC  cVr#iRt&iGcLaFl1lQyC.P

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026