PT-2026-97934 · Linux · Linux Kernel
CVE-2026-93247
·
Published
2026-09-24
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A NULL pointer dereference exists in the Bluetooth management component. The
uuid count member of the discovery state structure is accessed and modified without proper locking, creating a race condition. This can lead to a state where uuid count is non-zero while the uuids pointer is NULL. When the mgmt device found() function calls is filter match() and subsequently eir has uuids(), the inconsistent state triggers a kernel panic. The issue is further exacerbated if uuid count is assigned before a successful kmemdup() allocation in the start service discovery() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel