« Volver al listado

CVE-2026-98294

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_qca: Do not write to the serial port after it is closed

hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP is set (for example, for the WCN399x family). A failed hci_dev_open_sync() following a successful qca_setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs_on is left true. qca_serdev_remove() then passes its power->vregs_on test and calls qca_power_off(), which writes to the closed port unconditionally.

Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca_power_off() was still named qca_power_shutdown():

Leer descripción completaMostrar menos

Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down.

The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.

Detalles técnicos trazas, registros y código del informe original
  Unable to handle kernel NULL pointer dereference at virtual address
  0000000000000038
  Call trace:
   tty_set_termios+0x50/0x238 (P)
   ttyport_set_baudrate+0x84/0xc0
   serdev_device_set_baudrate+0x24/0x40
   qca_power_shutdown+0x158/0x1fc [hci_uart]
   qca_serdev_remove+0x54/0x68 [hci_uart]
   serdev_drv_remove+0x1c/0x2c
   device_remove+0x4c/0x80
   device_release_driver_internal+0x1cc/0x224
   device_driver_detach+0x18/0x24
   unbind_store+0xb4/0xc0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98294",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
              "lessThan": "a5414b0a9464b863733c8bd97493cb443a210ec4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
              "lessThan": "15754e4ec47ac5d117c9609c34a49ed6980ac4a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
              "lessThan": "4e93c65f87825e1e012bce56615320aeb123815d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/hci_qca.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/hci_qca.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:19.887",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15754e4ec47ac5d117c9609c34a49ed6980ac4a1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e93c65f87825e1e012bce56615320aeb123815d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5414b0a9464b863733c8bd97493cb443a210ec4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: Do not write to the serial port after it is closed\n\nhci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP\nis set (for example, for the WCN399x family). A failed hci_dev_open_sync()\nfollowing a successful qca_setup() calls hdev->close() but not\nhdev->shutdown(), so the port is closed while power->vregs_on is left true.\nqca_serdev_remove() then passes its power->vregs_on test and calls\nqca_power_off(), which writes to the closed port unconditionally.\n\nSeen on a WCN3988 by unbinding the driver after a controller failure. The\ntrace below is from a 7.0.0 based kernel, where qca_power_off() was still\nnamed qca_power_shutdown():\n\n  Unable to handle kernel NULL pointer dereference at virtual address\n  0000000000000038\n  Call trace:\n   tty_set_termios+0x50/0x238 (P)\n   ttyport_set_baudrate+0x84/0xc0\n   serdev_device_set_baudrate+0x24/0x40\n   qca_power_shutdown+0x158/0x1fc [hci_uart]\n   qca_serdev_remove+0x54/0x68 [hci_uart]\n   serdev_drv_remove+0x1c/0x2c\n   device_remove+0x4c/0x80\n   device_release_driver_internal+0x1cc/0x224\n   device_driver_detach+0x18/0x24\n   unbind_store+0xb4/0xc0\n\nCheck HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place\nit closes the port, before writing to it. The regulator disable is left\nunconditional so the controller is still powered down.\n\nThe dangling serport->tty that turns this into a use-after-free is\naddressed in a separate patch."
    }
  ],
  "lastModified": "2026-10-06T09:18:19.887",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}