CVE-2026-64178
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while reading dev->name (just like bnep_get_connlist() does); otherwise the bnep_session() thread can concurrently free the net_device, which can for example be triggered by a concurrent bnep_del_connection(). (This UAF is fairly uninteresting from a security perspective; calling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN) check. It also requires completely tearing down a netdev during a fairly tight race window.)
Schwachstellenklasse
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while reading dev->name (just like bnep_get_connlist() does); otherwise the bnep_session() thread can concurrently free the net_device, which can for example be triggered by a concurrent bnep_del_connection(). (This UAF is fairly uninteresting from a security perspective; calling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN) check. It also requires completely tearing down a netdev during a fairly tight race window.)
Betroffene Produkte
- linux linux_kernel
Quellen
- https://git.kernel.org/stable/c/4907596f25b1720fa948371ac5f6c1f8da10a5bc
- https://git.kernel.org/stable/c/5506aec795135cdd4cbf4e845929155663b25055
- https://git.kernel.org/stable/c/59e932ded949fa6f0340bf7c6d7818f962fa4fd2
- https://git.kernel.org/stable/c/915a92182e2cda9cd7d2479020a44c6eda986f7c
- https://git.kernel.org/stable/c/a75bbcb10cb21acc169b785e9804f57d97873a9c
- https://git.kernel.org/stable/c/b21805258d7e926adfd455fc820a447b90da3b82
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.