Описание
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: fix use-after-free on marvell probe failure
Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback.
This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: fix use-after-free on marvell probe failure
Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback.
This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-64470
- https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4
- https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed
- https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8
- https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af
- https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a
- https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e
- https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2
- https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79
EPSS
CVE ID
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on marvell probe failure Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.
A flaw was found in the Linux kernel's Bluetooth USB (btusb) driver. This vulnerability occurs during the Marvell Out-Of-Band (OOB) wakeup configuration when a probe failure happens. An attacker could potentially exploit a use-after-free condition in the completion callback, which may lead to system instability, denial of service, or potentially arbitrary code execution.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on marvell probe failure Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.
In the Linux kernel, the following vulnerability has been resolved: B ...
EPSS