← Späť na vyhľadávanie CVE

CVE-2026-53073

Linux Kernel

Popis

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to NULL. This means incoming UART data will reach the protocol-specific recv handler in hci_uart_tty_receive() after resources are freed. Clear HCI_UART_PROTO_INIT with a write lock before calling hu->proto->close() and setting hu->hdev to NULL. The write lock ensures all active readers have completed and no new reader can enter the protocol recv path before resources are freed. This allows the protocol-specific recv functions to remove the -HCI_UART_REGISTERED- guard without risking a null pointer dereference if hci_register_dev() fails.

CVSS 5.5EPSS 0.11399999999999999%Riziko 0.56
Zobraziť zdroj
Zverejnené
2026-06-24 17:17:21
Dotknuté verzie
unknown
Typ
Jadro
Posledná úprava
2026-07-21 18:05:01
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Operačné systémy
Linux