« Volver al listado

CVE-2026-97977

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: Fix UAF of btusb_data by rx_work

btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.

btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data:

Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.

Detalles técnicos trazas, registros y código del informe original
	while ((skb = skb_dequeue(&data->acl_q)))
		data->recv_acl(data->hdev, skb);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97977",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "fc654a72a8d979db15e2773a481e931abaf5a9e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "5242050195a711e9cd6a9935f689ab6656b94a91",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "472d005622525b7be155cac99dde2252b0163bd1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "93b59937bda3fffc6386c79f5544a39bc680c8e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "fa391adb9c755515a89993634745e9079e5ef37c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "800fe5ec302e1ebbf5e3f891f886deecd49c7132",
              "lessThan": "1c12c3117639e78940959d956519c758c57d0849",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btusb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btusb.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:25.680",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1c12c3117639e78940959d956519c758c57d0849",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/472d005622525b7be155cac99dde2252b0163bd1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5242050195a711e9cd6a9935f689ab6656b94a91",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/93b59937bda3fffc6386c79f5544a39bc680c8e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fa391adb9c755515a89993634745e9079e5ef37c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fc654a72a8d979db15e2773a481e931abaf5a9e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: Fix UAF of btusb_data by rx_work\n\nbtusb_close() and btusb_flush() cancel data->rx_work with the\nasynchronous cancel_delayed_work(), so if btusb_rx_work() is already\nrunning on another CPU it keeps running after the cancel returns.\n\nbtusb_disconnect() calls hci_unregister_dev(), which invokes\nbtusb_close(), and then frees the btusb_data. A still running\nbtusb_rx_work() then dereferences the freed data:\n\n\twhile ((skb = skb_dequeue(&data->acl_q)))\n\t\tdata->recv_acl(data->hdev, skb);\n\nUse cancel_delayed_work_sync() instead. In btusb_close() the cancel also\nhas to happen after btusb_stop_traffic(), otherwise an URB completion\nracing with the cancel can requeue the work right after it has been\nwaited for."
    }
  ],
  "lastModified": "2026-10-03T11:18:21.923",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}