PT-2026-106623 · Linux · Linux

CVE-2026-98294

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci qca: Do not write to the serial port after it is closed
hci uart close() closes the serdev port if HCI QUIRK NON PERSISTENT SETUP is set (for example, for the WCN399x family). A failed hci dev open sync() following a successful qca setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs on is left true. qca serdev remove() then passes its power->vregs on test and calls qca power off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca power off() was still named qca power shutdown():
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: tty set termios+0x50/0x238 (P) ttyport set baudrate+0x84/0xc0 serdev device set baudrate+0x24/0x40 qca power shutdown+0x158/0x1fc [hci uart] qca serdev remove+0x54/0x68 [hci uart] serdev drv remove+0x1c/0x2c device remove+0x4c/0x80 device release driver internal+0x1cc/0x224 device driver detach+0x18/0x24 unbind store+0xb4/0xc0
Check HCI UART PROTO READY, which hci uart close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98294

Produtos afetados

Linux