« Volver al listado

CVE-2026-64433

Estado: AnalizadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete

add_device_complete() runs from the hci_cmd_sync_work kworker, which holds only hci_req_sync_lock and *not* hci_dev_lock. It calls hci_conn_params_lookup() and then dereferences the returned object (params->flags) without taking hci_dev_lock:

hci_conn_params_lookup() walks hdev->le_conn_params and is documented to require hdev->lock. A concurrent MGMT_OP_REMOVE_DEVICE (remove_device()), which does run under hci_dev_lock, can call hci_conn_params_free() to list_del() and kfree() the very object the lookup returned, so the subsequent params->flags read touches freed memory [0].

Leer descripción completaMostrar menos

Hold hci_dev_lock() across the hci_conn_params_lookup() and the read of params->flags (and the matching event emission) so the lookup result cannot be freed by a concurrent remove_device() before it is used, honouring the locking contract of hci_conn_params_lookup().

Detalles técnicos trazas, registros y código del informe original
	params = hci_conn_params_lookup(hdev, &cp->addr.bdaddr,
					le_addr_type(cp->addr.type));
	...
	device_flags_changed(NULL, hdev, &cp->addr.bdaddr,
			     cp->addr.type, hdev->conn_flags,
			     params ? params->flags : 0);

[0]: (trailing page/memory-state dump trimmed)
BUG: KASAN: slab-use-after-free in add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671
Read of size 1 at addr ffff000017ab26c1 by task kworker/u9:8/388

CPU: 1 UID: 0 PID: 388 Comm: kworker/u9:8 Not tainted 7.0.11 #20 PREEMPT
Hardware name: linux,dummy-virt (DT)
Workqueue: hci0 hci_cmd_sync_work
Call trace:
 show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xb4/0xd4 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:378 [inline]
 print_report+0x118/0x5d8 mm/kasan/report.c:482
 kasan_report+0xb0/0xf4 mm/kasan/report.c:595
 __asan_report_load1_noabort+0x20/0x2c mm/kasan/report_generic.c:378
 add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671
 hci_cmd_sync_work+0x14c/0x240 net/bluetooth/hci_sync.c:334
 process_one_work+0x628/0xd38 kernel/workqueue.c:3289
 process_scheduled_works kernel/workqueue.c:3372 [inline]
 worker_thread+0x7a8/0xac0 kernel/workqueue.c:3453
 kthread+0x39c/0x444 kernel/kthread.c:436
 ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860

Allocated by task 3401:
 kasan_save_stack+0x3c/0x64 mm/kasan/common.c:57
 kasan_save_track+0x20/0x3c mm/kasan/common.c:78
 kasan_save_alloc_info+0x40/0x54 mm/kasan/generic.c:570
 poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
 __kasan_kmalloc+0xd4/0xd8 mm/kasan/common.c:415
 kasan_kmalloc include/linux/kasan.h:263 [inline]
 __kmalloc_cache_noprof+0x1b0/0x458 mm/slub.c:5385
 kmalloc_noprof include/linux/slab.h:950 [inline]
 kzalloc_noprof include/linux/slab.h:1188 [inline]
 hci_conn_params_add+0x10c/0x4b0 net/bluetooth/hci_core.c:2279
 hci_conn_params_set net/bluetooth/mgmt.c:5162 [inline]
 add_device+0x5b4/0xa54 net/bluetooth/mgmt.c:7755
 hci_mgmt_cmd net/bluetooth/hci_sock.c:1721 [inline]
 hci_sock_sendmsg+0x10b4/0x1dd0 net/bluetooth/hci_sock.c:1841
 sock_sendmsg_nosec net/socket.c:727 [inline]
 __sock_sendmsg+0xe0/0x128 net/socket.c:742
 sock_write_iter+0x250/0x390 net/socket.c:1195
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x66c/0xab0 fs/read_write.c:688
 ksys_write+0x1fc/0x24c fs/read_write.c:740
 __do_sys_write fs/read_write.c:751 [inline]
 __se_sys_write fs/read_write.c:748 [inline]
 __arm64_sys_write+0x70/0xa4 fs/read_write.c:748
 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
 invoke_syscall+0x84/0x2a8 arch/arm64/kernel/syscall.c:49
 el0_svc_common.constprop.0+0xe4/0x294 arch/arm64/kernel/syscall.c:132
 do_el0_svc+0x44/0x5c arch/arm64/kernel/syscall.c:151
 el0_svc+0x38/0xac arch/arm64/kernel/entry-common.c:724
 el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:743
 el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596

Freed by task 3740:
 kasan_save_stack+0x3c/0x64 
---truncated---

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UAF local en kernel Bluetooth (CWE-416, AV:L/PR:L) permite DoS por crash; acceso local con privilegios permite escalada o corrupción de memoria del kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64433",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "31492b8386e5a243df26ca4a9421f6b041f414d5",
              "lessThan": "caed4a96d55757c139a899744657c032b6186665",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28826a89fdfd49f3291980c2e68b8a7c5d55e199",
              "lessThan": "e4369e4e970f3fa4676b76be14c1d315c87f22b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
              "lessThan": "b346efa825b5e4386f19bc63f81141652d496ec4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
              "lessThan": "9531014c60c804e16099885d4a98aedcf31bce8d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
              "lessThan": "fa85d985f614bc3feb343000f14a1072e99b0df1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7e370545b8bdb54ed7f1ae485d6d24d3b62a0b53",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.92",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.30",
              "lessThan": "6.12.96",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.14.8",
              "lessThan": "6.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:27.567",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/9531014c60c804e16099885d4a98aedcf31bce8d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b346efa825b5e4386f19bc63f81141652d496ec4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/caed4a96d55757c139a899744657c032b6186665",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e4369e4e970f3fa4676b76be14c1d315c87f22b6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fa85d985f614bc3feb343000f14a1072e99b0df1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete\n\nadd_device_complete() runs from the hci_cmd_sync_work kworker, which\nholds only hci_req_sync_lock and *not* hci_dev_lock.  It calls\nhci_conn_params_lookup() and then dereferences the returned object\n(params->flags) without taking hci_dev_lock:\n\n\tparams = hci_conn_params_lookup(hdev, &cp->addr.bdaddr,\n\t\t\t\t\tle_addr_type(cp->addr.type));\n\t...\n\tdevice_flags_changed(NULL, hdev, &cp->addr.bdaddr,\n\t\t\t     cp->addr.type, hdev->conn_flags,\n\t\t\t     params ? params->flags : 0);\n\nhci_conn_params_lookup() walks hdev->le_conn_params and is documented to\nrequire hdev->lock.  A concurrent MGMT_OP_REMOVE_DEVICE\n(remove_device()), which does run under hci_dev_lock, can call\nhci_conn_params_free() to list_del() and kfree() the very object the\nlookup returned, so the subsequent params->flags read touches freed\nmemory [0].\n\nHold hci_dev_lock() across the hci_conn_params_lookup() and the read of\nparams->flags (and the matching event emission) so the lookup result\ncannot be freed by a concurrent remove_device() before it is used,\nhonouring the locking contract of hci_conn_params_lookup().\n\n[0]: (trailing page/memory-state dump trimmed)\nBUG: KASAN: slab-use-after-free in add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\nRead of size 1 at addr ffff000017ab26c1 by task kworker/u9:8/388\n\nCPU: 1 UID: 0 PID: 388 Comm: kworker/u9:8 Not tainted 7.0.11 #20 PREEMPT\nHardware name: linux,dummy-virt (DT)\nWorkqueue: hci0 hci_cmd_sync_work\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xb4/0xd4 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x118/0x5d8 mm/kasan/report.c:482\n kasan_report+0xb0/0xf4 mm/kasan/report.c:595\n __asan_report_load1_noabort+0x20/0x2c mm/kasan/report_generic.c:378\n add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\n hci_cmd_sync_work+0x14c/0x240 net/bluetooth/hci_sync.c:334\n process_one_work+0x628/0xd38 kernel/workqueue.c:3289\n process_scheduled_works kernel/workqueue.c:3372 [inline]\n worker_thread+0x7a8/0xac0 kernel/workqueue.c:3453\n kthread+0x39c/0x444 kernel/kthread.c:436\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860\n\nAllocated by task 3401:\n kasan_save_stack+0x3c/0x64 mm/kasan/common.c:57\n kasan_save_track+0x20/0x3c mm/kasan/common.c:78\n kasan_save_alloc_info+0x40/0x54 mm/kasan/generic.c:570\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xd4/0xd8 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __kmalloc_cache_noprof+0x1b0/0x458 mm/slub.c:5385\n kmalloc_noprof include/linux/slab.h:950 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n hci_conn_params_add+0x10c/0x4b0 net/bluetooth/hci_core.c:2279\n hci_conn_params_set net/bluetooth/mgmt.c:5162 [inline]\n add_device+0x5b4/0xa54 net/bluetooth/mgmt.c:7755\n hci_mgmt_cmd net/bluetooth/hci_sock.c:1721 [inline]\n hci_sock_sendmsg+0x10b4/0x1dd0 net/bluetooth/hci_sock.c:1841\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg+0xe0/0x128 net/socket.c:742\n sock_write_iter+0x250/0x390 net/socket.c:1195\n new_sync_write fs/read_write.c:595 [inline]\n vfs_write+0x66c/0xab0 fs/read_write.c:688\n ksys_write+0x1fc/0x24c fs/read_write.c:740\n __do_sys_write fs/read_write.c:751 [inline]\n __se_sys_write fs/read_write.c:748 [inline]\n __arm64_sys_write+0x70/0xa4 fs/read_write.c:748\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x84/0x2a8 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0xe4/0x294 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x44/0x5c arch/arm64/kernel/syscall.c:151\n el0_svc+0x38/0xac arch/arm64/kernel/entry-common.c:724\n el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:743\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596\n\nFreed by task 3740:\n kasan_save_stack+0x3c/0x64 \n---truncated---"
    }
  ],
  "lastModified": "2026-09-03T18:26:49.233",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B01BC9E9-86E5-4B71-917E-5F5B2C3D316D",
              "versionEndExcluding": "6.6.145",
              "versionStartIncluding": "6.6.92"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "231480E4-B71C-4F3A-8C32-E91644C04A24",
              "versionEndExcluding": "6.12.96",
              "versionStartIncluding": "6.12.30"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F41DF25A-BF6E-49BA-950C-6BD0DA29BE5A",
              "versionEndExcluding": "6.15",
              "versionStartIncluding": "6.14.8"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41F5254B-116D-4B17-A619-0B6550F3496A",
              "versionEndExcluding": "6.18.39",
              "versionStartIncluding": "6.15.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
              "versionEndExcluding": "7.1.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1ECC65A-EE37-4479-8E99-4BB68A22A31F"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C300BA32-5854-4B59-A00A-18A402F291D0"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E8B9085-7ADB-4A05-89EF-12949B6A0509"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FC0D50D-9D58-4947-A197-A5A3FF07E7E3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}