« Volver al listado

CVE-2026-98295

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98295",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9695ef876fd122cb7bbc04a4a93b8727d2e36bda",
              "lessThan": "24af375d7d8aa5f698e4dc41317102f44114351a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9695ef876fd122cb7bbc04a4a93b8727d2e36bda",
              "lessThan": "dcaf10ef27f928568c25de3e9fc242e538de5c67",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9695ef876fd122cb7bbc04a4a93b8727d2e36bda",
              "lessThan": "82699d1b727ba5980b94f1eb8dc3d346f41b7c67",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9695ef876fd122cb7bbc04a4a93b8727d2e36bda",
              "lessThan": "d236517c264e41dc09833c708ef23bccb7a91219",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "deb8156ebe5cb63a5988e7f86cc46aa062527c2b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.188",
              "lessThan": "6.2",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/net/bluetooth/coredump.h",
            "net/bluetooth/coredump.c",
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/bluetooth/coredump.h",
            "net/bluetooth/coredump.c",
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:20.133",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: coredump: Quiesce dump work on unregister\n\nhci_devcd_handle_pkt_init() arms dump_timeout and coredump producers\nqueue dump_rx without holding an hdev reference. Unregister leaves both\nworks live, so disconnecting during an active dump lets them access hdev\nafter hci_release_dev() frees it.\n\nShut down coredump processing during unregister. Close the producer gate\nunder dump_q.lock before disabling both works, then free the active buffer\nand queued packets under hci_dev_lock. Serializing the gate with enqueue\nprevents controller-specific workers from adding packets after the final\npurge."
    }
  ],
  "lastModified": "2026-10-06T09:18:20.133",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}