{"apiVersion":"1.0","identifier":"CVE-2026-74304","description":"In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device hu->serdev is NULL for hci_uart attached via non-serdev paths, but qca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev) and dereferences the result, causing a NULL pointer dereference. Fix by guarding the dereference with a NULL check, consistent with the rest of qca_setup().","publishedAt":"2026-08-15T06:22:30","lastModifiedAt":"2026-08-17T06:19:24","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74304","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00155,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74304","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74304","en":"https://www.redsauce.net/en/cves/CVE-2026-74304","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74304","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74304","de":"https://www.redsauce.net/de/cves/CVE-2026-74304","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74304","el":"https://www.redsauce.net/el/cves/CVE-2026-74304"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74304"}}