PT-2026-64629 · Linux+1 · Linux Kernel+1

CVE-2026-64408

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth BNEP (Bluetooth Network Encapsulation Protocol) component where the bnep add connection() function reads the L2CAP connection without holding the channel lock before passing the HCI device to register netdev(). This creates a race condition during controller teardown, which can clear and release the connection concurrently, leading the network device registration path to dereference a freed parent device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93788
CVE-2026-64408
ECHO-78B6-E52B-625B
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu