« Volver al listado

CVE-2026-93247

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference

'uuid_count' member of struct 'discovery_state' is assigned and read without any locks, so there is a chance of situation when uuid_count != 0, but uuids is NULL and there will be NULL pointer dereference.

Now uuids == NULL and uuid_count != 0. So 'mgmt_device_found' -> 'is_filter_match' -> 'eir_has_uuids' receives non consistent discovery state, where NULL dereference of uuids happens.

To fix it let's add discovery.lock around every read/write of uuid_count, uuids pair of struct members.

Leer descripción completaMostrar menos

It is also important to assign uuid_count value only after success kmemdup() allocation in start_service_discovery(), otherwise uuids is NULL, because kmemdup failed, but uuid_count is already assigned to non zero value.

The following panic happens:

Detalles técnicos trazas, registros y código del informe original
Possible race:
'hci_update_passive_scan_sync'
  'hci_discovery_filter_clear'
    hdev->discovery.uuid_count = 0;
      <----------------------preempted----------------------------->
                        'start_service_discovery'
                          // Set uuid_count to value != 0
                          hdev->discovery.uuid_count = uuid_count;
                          hdev->discovery.uuids = kmemdup(...);
      <----------------------preempted----------------------------->
    spin_lock(&hdev->discovery.lock);
    kfree(hdev->discovery.uuids);
    hdev->discovery.uuids = NULL;
    spin_unlock(&hdev->discovery.lock);

[ ] ------------[ cut here ]------------
[ ] Unable to handle kernel NULL pointer dereference at virtual
address 0000000000000000
[ ] Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP
[ ] CPU: 0 PID: 15056 Comm: kworker/u9:2
[ ] Workqueue: hci0 hci_rx_work
[ ] pstate: 10400009 (nzcV daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ ] pc : eir_has_uuids+0x2d8/0x590
[ ] lr : is_filter_match+0x258/0x320
...
[ ] Call trace:
[ ]  eir_has_uuids+0x2d8/0x590
[ ]  is_filter_match+0x258/0x320
[ ]  mgmt_device_found+0x5b0/0xafc
[ ]  process_adv_report.part.0+0x8c8/0xf14
[ ]  hci_le_adv_report_evt+0x338/0x3f0
[ ]  hci_le_meta_evt+0x1f0/0x4c8
[ ]  hci_event_packet+0x440/0xc9c
[ ]  hci_rx_work+0x44c/0xaf8
[ ]  process_one_work+0x54c/0x103c
[ ]  worker_thread+0x6c4/0x10c4
[ ]  kthread+0x274/0x2ec
[ ]  ret_from_fork+0x10/0x20
[ ] Code: 14000004 91004021 eb14003f 54000180 (f9400024)
[ ] ---[ end trace 0000000000000000 ]---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93247",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "86f3dcd1f331cfd4fd7ec88906955134ec51afbe",
              "lessThan": "f02c01ccd12cb2b8a290077d4c90f29a6e109b16",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7ce9bb0b95fc280e9212b8922590c492ca1d9c39",
              "lessThan": "bbd262d2d750b67b15a5e1008d3848309c87e7a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16852eccbdfaf41a666705e3f8be55cf2864c5ca",
              "lessThan": "18fda026a13c5abd6c1e0dfd3549f490b73378fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2935e556850e9c94d7a00adf14d3cd7fe406ac03",
              "lessThan": "c3f63610bceaa182e4683b23cc47baf36b5f1496",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2935e556850e9c94d7a00adf14d3cd7fe406ac03",
              "lessThan": "ee2135a14fb2a3e176149122764d293f0796b1eb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2935e556850e9c94d7a00adf14d3cd7fe406ac03",
              "lessThan": "59eecbe2f2f38d8f3e1104bd11da97f9a2c58998",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a351ff6b8ecca4229afaa0d98042bead8de64799",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f8069f34c4c976786ded97498012225af87435d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.159",
              "lessThan": "6.1.188",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.117",
              "lessThan": "6.6.157",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.42",
              "lessThan": "6.12.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.10",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.16.1",
              "lessThan": "6.17",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/net/bluetooth/hci_core.h",
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/bluetooth/hci_core.h",
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:20.803",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/18fda026a13c5abd6c1e0dfd3549f490b73378fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59eecbe2f2f38d8f3e1104bd11da97f9a2c58998",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bbd262d2d750b67b15a5e1008d3848309c87e7a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3f63610bceaa182e4683b23cc47baf36b5f1496",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee2135a14fb2a3e176149122764d293f0796b1eb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f02c01ccd12cb2b8a290077d4c90f29a6e109b16",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference\n\n'uuid_count' member of struct 'discovery_state' is assigned and read\nwithout any locks, so there is a chance of situation when\nuuid_count != 0, but uuids is NULL and there will be NULL pointer\ndereference.\n\nPossible race:\n'hci_update_passive_scan_sync'\n  'hci_discovery_filter_clear'\n    hdev->discovery.uuid_count = 0;\n      <----------------------preempted----------------------------->\n                        'start_service_discovery'\n                          // Set uuid_count to value != 0\n                          hdev->discovery.uuid_count = uuid_count;\n                          hdev->discovery.uuids = kmemdup(...);\n      <----------------------preempted----------------------------->\n    spin_lock(&hdev->discovery.lock);\n    kfree(hdev->discovery.uuids);\n    hdev->discovery.uuids = NULL;\n    spin_unlock(&hdev->discovery.lock);\n\nNow uuids == NULL and uuid_count != 0.\nSo 'mgmt_device_found' -> 'is_filter_match' -> 'eir_has_uuids' receives\nnon consistent discovery state, where NULL dereference of uuids happens.\n\nTo fix it let's add discovery.lock around every read/write of uuid_count,\nuuids pair of struct members. It is also important to assign uuid_count\nvalue only after success kmemdup() allocation in\nstart_service_discovery(), otherwise uuids is NULL, because kmemdup failed,\nbut uuid_count is already assigned to non zero value.\n\nThe following panic happens:\n\n[ ] ------------[ cut here ]------------\n[ ] Unable to handle kernel NULL pointer dereference at virtual\naddress 0000000000000000\n[ ] Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP\n[ ] CPU: 0 PID: 15056 Comm: kworker/u9:2\n[ ] Workqueue: hci0 hci_rx_work\n[ ] pstate: 10400009 (nzcV daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ ] pc : eir_has_uuids+0x2d8/0x590\n[ ] lr : is_filter_match+0x258/0x320\n...\n[ ] Call trace:\n[ ]  eir_has_uuids+0x2d8/0x590\n[ ]  is_filter_match+0x258/0x320\n[ ]  mgmt_device_found+0x5b0/0xafc\n[ ]  process_adv_report.part.0+0x8c8/0xf14\n[ ]  hci_le_adv_report_evt+0x338/0x3f0\n[ ]  hci_le_meta_evt+0x1f0/0x4c8\n[ ]  hci_event_packet+0x440/0xc9c\n[ ]  hci_rx_work+0x44c/0xaf8\n[ ]  process_one_work+0x54c/0x103c\n[ ]  worker_thread+0x6c4/0x10c4\n[ ]  kthread+0x274/0x2ec\n[ ]  ret_from_fork+0x10/0x20\n[ ] Code: 14000004 91004021 eb14003f 54000180 (f9400024)\n[ ] ---[ end trace 0000000000000000 ]---"
    }
  ],
  "lastModified": "2026-09-24T16:17:20.803",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}