PT-2026-64626 · Linux+1 · Linux Kernel+1

CVE-2026-64405

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null pointer dereference exists in the Bluetooth component. The hci abort conn() function reads hci skb event(hdev->sent cmd) during a pending connection; however, hdev->sent cmd can be NULL while req status remains HCI REQ PEND. This leads to a general protection fault within the hci rx work() receive path. Additionally, a use-after-free condition could occur if the command status handler frees the connection via hci conn del() while the worker is blocked on the connection complete event.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93452
CVE-2026-64405
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu