PT-2026-106623 · Linux · Linux
CVE-2026-98294
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci qca: Do not write to the serial port after it is closed
hci uart close() closes the serdev port if HCI QUIRK NON PERSISTENT SETUP
is set (for example, for the WCN399x family). A failed hci dev open sync()
following a successful qca setup() calls hdev->close() but not
hdev->shutdown(), so the port is closed while power->vregs on is left true.
qca serdev remove() then passes its power->vregs on test and calls
qca power off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The
trace below is from a 7.0.0 based kernel, where qca power off() was still
named qca power shutdown():
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000038
Call trace:
tty set termios+0x50/0x238 (P)
ttyport set baudrate+0x84/0xc0
serdev device set baudrate+0x24/0x40
qca power shutdown+0x158/0x1fc [hci uart]
qca serdev remove+0x54/0x68 [hci uart]
serdev drv remove+0x1c/0x2c
device remove+0x4c/0x80
device release driver internal+0x1cc/0x224
device driver detach+0x18/0x24
unbind store+0xb4/0xc0
Check HCI UART PROTO READY, which hci uart close() clears in the same place
it closes the port, before writing to it. The regulator disable is left
unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is
addressed in a separate patch.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux