CVE-2026-98294
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_qca: Do not write to the serial port after it is closed
hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP is set (for example, for the WCN399x family). A failed hci_dev_open_sync() following a successful qca_setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs_on is left true. qca_serdev_remove() then passes its power->vregs_on test and calls qca_power_off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca_power_off() was still named qca_power_shutdown():
Leer descripción completaMostrar menos
Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.
Detalles técnicos trazas, registros y código del informe original
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: tty_set_termios+0x50/0x238 (P) ttyport_set_baudrate+0x84/0xc0 serdev_device_set_baudrate+0x24/0x40 qca_power_shutdown+0x158/0x1fc [hci_uart] qca_serdev_remove+0x54/0x68 [hci_uart] serdev_drv_remove+0x1c/0x2c device_remove+0x4c/0x80 device_release_driver_internal+0x1cc/0x224 device_driver_detach+0x18/0x24 unbind_store+0xb4/0xc0
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98294",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
"lessThan": "a5414b0a9464b863733c8bd97493cb443a210ec4",
"versionType": "git"
},
{
"status": "affected",
"version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
"lessThan": "15754e4ec47ac5d117c9609c34a49ed6980ac4a1",
"versionType": "git"
},
{
"status": "affected",
"version": "fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3",
"lessThan": "4e93c65f87825e1e012bce56615320aeb123815d",
"versionType": "git"
}
],
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:19.887",
"references": [
{
"url": "https://git.kernel.org/stable/c/15754e4ec47ac5d117c9609c34a49ed6980ac4a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4e93c65f87825e1e012bce56615320aeb123815d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5414b0a9464b863733c8bd97493cb443a210ec4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: Do not write to the serial port after it is closed\n\nhci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP\nis set (for example, for the WCN399x family). A failed hci_dev_open_sync()\nfollowing a successful qca_setup() calls hdev->close() but not\nhdev->shutdown(), so the port is closed while power->vregs_on is left true.\nqca_serdev_remove() then passes its power->vregs_on test and calls\nqca_power_off(), which writes to the closed port unconditionally.\n\nSeen on a WCN3988 by unbinding the driver after a controller failure. The\ntrace below is from a 7.0.0 based kernel, where qca_power_off() was still\nnamed qca_power_shutdown():\n\n Unable to handle kernel NULL pointer dereference at virtual address\n 0000000000000038\n Call trace:\n tty_set_termios+0x50/0x238 (P)\n ttyport_set_baudrate+0x84/0xc0\n serdev_device_set_baudrate+0x24/0x40\n qca_power_shutdown+0x158/0x1fc [hci_uart]\n qca_serdev_remove+0x54/0x68 [hci_uart]\n serdev_drv_remove+0x1c/0x2c\n device_remove+0x4c/0x80\n device_release_driver_internal+0x1cc/0x224\n device_driver_detach+0x18/0x24\n unbind_store+0xb4/0xc0\n\nCheck HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place\nit closes the port, before writing to it. The regulator disable is left\nunconditional so the controller is still powered down.\n\nThe dangling serport->tty that turns this into a use-after-free is\naddressed in a separate patch."
}
],
"lastModified": "2026-10-06T09:18:19.887",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}