PT-2026-98639 · Linux · Linux
CVE-2026-97975
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci sysfs: Fix NULL pointer dereference in device del()
A NULL pointer dereference in klist put() occurs when a child device (such
as a BNEP network device in bnep session) is concurrently being
unregistered while hci conn del sysfs() reparents child devices.
This is caused by a race condition between hci conn del sysfs() and
concurrent child device unregistration (e.g. bnep session calling
unregister netdev()). During device unregistration, device del() snapshots
a non-NULL parent pointer. Concurrently, hci conn del sysfs() finds the
child device using device find any child() and calls device move() to
reparent it to NULL, which removes the node from its parent's klist and
clears knode parent. Subsequently, device del() calls
klist del(&dev->p->knode parent) using the stale parent snapshot, causing
klist put() to dereference knode klist(n)->put on an already removed node,
resulting in a NULL pointer dereference.
This race was introduced by commit 27aabf27fd01 ("Bluetooth: fix
use-after-free in device for each child()"), which replaced
device find child(..., match tty) with device find any child() in
hci conn del sysfs(). That change was intended to avoid a use-after-free
where conn->dev outlived its parent hdev->dev when child devices held
references to conn->dev, because conn->dev only held a reference to
hdev->dev while registered in sysfs.
Fix the issue properly by taking an explicit reference to the parent device
with get device(&hdev->dev) in hci conn init sysfs() and dropping it with
put device(parent) in bt link release() when the conn device is freed. This
ensures that hdev->dev remains valid for the entire lifecycle of conn->dev,
resolving the underlying use-after-free. With the parent reference held
properly, restore the match tty filter in hci conn del sysfs() so that
device move() is only invoked on persistent RFCOMM TTY devices as
originally intended, eliminating the race condition with unregistering
network devices.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux