CVE-2026-64470 PUBLISHED

Bluetooth: btusb: fix use-after-free on marvell probe failure

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: fix use-after-free on marvell probe failure

Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback.

This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 1edd524de5cc8143ece9c42c466346983dc5b5ed (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 0ccb1cb0a464dab78284c34196cd3e8e18bab4c4 (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 631de465aba7f8ae46478bf5f598111412e8eff8 (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 6e1b10df890f4663cb38af9fc1c93d36747b75af (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 92c736866244340497a8a65afe2ac25354c2bf5e (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to a7e941a395711791c7e98d9870c6562c2c9e9ef2 (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to 838c917a2f16eefe68def800ebf48a2af591149a (excl.)
  • affected from a4ccc9e33d2f01532bcceb621ea06bbf4db6efac to c5b600a3c05b1a7a110d558df935a8fc8a471c79 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.11 is affected
  • unaffected from 0 to 4.11 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References