PT-2026-98639 · Linux · Linux

CVE-2026-97975

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci sysfs: Fix NULL pointer dereference in device del()
A NULL pointer dereference in klist put() occurs when a child device (such as a BNEP network device in bnep session) is concurrently being unregistered while hci conn del sysfs() reparents child devices.
This is caused by a race condition between hci conn del sysfs() and concurrent child device unregistration (e.g. bnep session calling unregister netdev()). During device unregistration, device del() snapshots a non-NULL parent pointer. Concurrently, hci conn del sysfs() finds the child device using device find any child() and calls device move() to reparent it to NULL, which removes the node from its parent's klist and clears knode parent. Subsequently, device del() calls klist del(&dev->p->knode parent) using the stale parent snapshot, causing klist put() to dereference knode klist(n)->put on an already removed node, resulting in a NULL pointer dereference.
This race was introduced by commit 27aabf27fd01 ("Bluetooth: fix use-after-free in device for each child()"), which replaced device find child(..., match tty) with device find any child() in hci conn del sysfs(). That change was intended to avoid a use-after-free where conn->dev outlived its parent hdev->dev when child devices held references to conn->dev, because conn->dev only held a reference to hdev->dev while registered in sysfs.
Fix the issue properly by taking an explicit reference to the parent device with get device(&hdev->dev) in hci conn init sysfs() and dropping it with put device(parent) in bt link release() when the conn device is freed. This ensures that hdev->dev remains valid for the entire lifecycle of conn->dev, resolving the underlying use-after-free. With the parent reference held properly, restore the match tty filter in hci conn del sysfs() so that device move() is only invoked on persistent RFCOMM TTY devices as originally intended, eliminating the race condition with unregistering network devices.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97975

Produtos afetados

Linux