« Volver al listado

CVE-2026-80764

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_event: fix LE list UAF on reset

hci_cc_reset() clears the LE accept and resolving lists without taking hdev->lock. Other command-complete handlers serialize updates to these lists with that lock, and the debugfs readers hold it while walking them.

This permits the reset completion and a debugfs read to interleave as follows:

The reader then dereferences a freed list entry and may follow its stale next pointer.

Take hdev->lock around both list clears. This matches the existing mutation and traversal locking convention.

Detalles técnicos trazas, registros y código del informe original
  hci_rx_work                 debugfs reader
  -----------                 --------------
                              lock hdev->lock
                              fetch current entry
  list_del(entry)
  kfree(entry)
                              read entry fields

KASAN reported:

  BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180
  Read of size 1 at addr ffff8881015dab16 by task poc/95

  Call Trace:
   white_list_show+0x15f/0x180
   seq_read_iter+0x3ff/0x1190
   seq_read+0x267/0x3d0
   vfs_read+0x177/0xa20
   ksys_read+0xf7/0x1c0

  Allocated by task 91:
   hci_bdaddr_list_add+0x1a6/0x3a0
   hci_cc_le_add_to_accept_list+0xab/0x140
   hci_cmd_complete_evt+0x26c/0x9a0
   hci_event_packet+0x454/0xb20
   hci_rx_work+0x293/0x730

  Freed by task 90:
   kfree+0x131/0x3c0
   hci_bdaddr_list_clear+0xd8/0x160
   hci_cc_reset+0x28a/0x370
   hci_cmd_complete_evt+0x26c/0x9a0
   hci_event_packet+0x454/0xb20
   hci_rx_work+0x293/0x730

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80764",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "8e68c380290b1dd64a0a512ce66d0264130c46ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "0628cc9b2fa29985a7b8c774741f8a736b0f5e7c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "d57702d4c55633c243da5a2fec37ae2ad4adb621",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "39a3afb91be3cb465f46ce7a8e5696d9e33edf93",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "b55e83a4ba31d40deae22d4e4dc8c84083e953c6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "25b05e3ce31d954540e99954bcc66cbceb27ab35",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
              "lessThan": "33af47e847fe4a28b109673affb5874015d54f5a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0de8cd646b0152c9ddd10257d8284938d0df0181",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3.18.3",
              "lessThan": "3.19",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_event.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_event.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:01.617",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0628cc9b2fa29985a7b8c774741f8a736b0f5e7c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/25b05e3ce31d954540e99954bcc66cbceb27ab35",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/33af47e847fe4a28b109673affb5874015d54f5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/39a3afb91be3cb465f46ce7a8e5696d9e33edf93",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8e68c380290b1dd64a0a512ce66d0264130c46ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b55e83a4ba31d40deae22d4e4dc8c84083e953c6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d57702d4c55633c243da5a2fec37ae2ad4adb621",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: fix LE list UAF on reset\n\nhci_cc_reset() clears the LE accept and resolving lists without taking\nhdev->lock. Other command-complete handlers serialize updates to these\nlists with that lock, and the debugfs readers hold it while walking them.\n\nThis permits the reset completion and a debugfs read to interleave as\nfollows:\n\n  hci_rx_work                 debugfs reader\n  -----------                 --------------\n                              lock hdev->lock\n                              fetch current entry\n  list_del(entry)\n  kfree(entry)\n                              read entry fields\n\nThe reader then dereferences a freed list entry and may follow its stale\nnext pointer.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180\n  Read of size 1 at addr ffff8881015dab16 by task poc/95\n\n  Call Trace:\n   white_list_show+0x15f/0x180\n   seq_read_iter+0x3ff/0x1190\n   seq_read+0x267/0x3d0\n   vfs_read+0x177/0xa20\n   ksys_read+0xf7/0x1c0\n\n  Allocated by task 91:\n   hci_bdaddr_list_add+0x1a6/0x3a0\n   hci_cc_le_add_to_accept_list+0xab/0x140\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\n  Freed by task 90:\n   kfree+0x131/0x3c0\n   hci_bdaddr_list_clear+0xd8/0x160\n   hci_cc_reset+0x28a/0x370\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\nTake hdev->lock around both list clears. This matches the existing\nmutation and traversal locking convention."
    }
  ],
  "lastModified": "2026-09-04T16:18:01.617",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}