PT-2026-106623 · Linux · Linux
CVE-2026-98294
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci qca: Do not write to the serial port after it is closed
hci uart close() closes the serdev port if HCI QUIRK NON PERSISTENT SETUP
is set (for example, for the WCN399x family). A failed hci dev open sync()
following a successful qca setup() calls hdev->close() but not
hdev->shutdown(), so the port is closed while power->vregs on is left true.
qca serdev remove() then passes its power->vregs on test and calls
qca power off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The
trace below is from a 7.0.0 based kernel, where qca power off() was still
named qca power shutdown():
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000038
Call trace:
tty set termios+0x50/0x238 (P)
ttyport set baudrate+0x84/0xc0
serdev device set baudrate+0x24/0x40
qca power shutdown+0x158/0x1fc [hci uart]
qca serdev remove+0x54/0x68 [hci uart]
serdev drv remove+0x1c/0x2c
device remove+0x4c/0x80
device release driver internal+0x1cc/0x224
device driver detach+0x18/0x24
unbind store+0xb4/0xc0
Check HCI UART PROTO READY, which hci uart close() clears in the same place
it closes the port, before writing to it. The regulator disable is left
unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is
addressed in a separate patch.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux