Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-64408

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-64408

7 дней назад

A flaw was found in the Bluetooth Network Encapsulation Protocol (BNEP) module of the Linux kernel. The `bnep_add_connection()` function reads the Logical Link Control and Adaptation Protocol (L2CAP) connection without properly holding a channel lock. This can allow a local attacker to trigger a use-after-free vulnerability during network device registration, potentially leading to a system crash and denial of service.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-64408

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-64408

6 дней назад

Bluetooth: bnep: pin L2CAP connection during netdev registration

EPSS: Низкий
debian логотип

CVE-2026-64408

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: B ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mgrm-7xvj-2jr3

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-64408

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-64408

A flaw was found in the Bluetooth Network Encapsulation Protocol (BNEP) module of the Linux kernel. The `bnep_add_connection()` function reads the Logical Link Control and Adaptation Protocol (L2CAP) connection without properly holding a channel lock. This can allow a local attacker to trigger a use-after-free vulnerability during network device registration, potentially leading to a system crash and denial of service.

CVSS3: 5.5
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-64408

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
0%
Низкий
7 дней назад
msrc логотип
CVE-2026-64408

Bluetooth: bnep: pin L2CAP connection during netdev registration

0%
Низкий
6 дней назад
debian логотип
CVE-2026-64408

In the Linux kernel, the following vulnerability has been resolved: B ...

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-mgrm-7xvj-2jr3

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.

CVSS3: 8.8
0%
Низкий
7 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.