PT-2026-70060 · Realtek · Bee Bluetooth Hci Driver

CVE-2026-11894

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.9

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Realtek BEE Bluetooth HCI driver (affected versions not specified)
Description The bt hci bee send() function in drivers/bluetooth/hci/hci bee.c violates the buffer-ownership contract of the bt hci driver api. The driver incorrectly releases the transmit net buf during error paths, while the host caller also releases the same buffer upon receiving an error. This results in a double-free condition that corrupts the shared net buf pool or causes a reference count underflow. Additionally, the driver attempts to read buf->len within a LOG ERR call after the buffer has been freed, leading to a use-after-free read. These conditions occur during host-to-controller buffer allocation failures or controller send failures, which can be indirectly triggered by a remote Bluetooth peer through heavy transmit activity, potentially causing the device to crash or suffer further memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11894
GHSA-V9MJ-H2M6-V9C6

Affected Products

Bee Bluetooth Hci Driver