CVE-2026-64471 PUBLISHED

Bluetooth: btusb: fix use-after-free on registration failure

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: fix use-after-free on registration failure

Make sure to release the sibling interfaces in case controller registration fails to avoid use-after-free and double-free when they are eventually disconnected.

This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to e09ac7d0c6859a360bf36e7104aef03f88184e0b (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to 468fcdfaeb937163dd250773a9fed17ab1fa203c (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to 1ce5012944afaddbda939ec6bae9800fce84abbc (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to e6313b800da61a26c2fdd5eba0105e197c0ab3bc (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to 14e02f1449ba425a44dedbec9a21efafb056e09f (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to 8db0ce3de78367f61c2970c0f16d9adee8830a23 (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to da7d7758fe884b256ddc9fef562e5ddef7952383 (excl.)
  • affected from 9bfa35fe422c74882e27cc54450a5f76c96aad68 to eedc6867ebad73edbfaf9a0a65fbef7115cc4753 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.27 is affected
  • unaffected from 0 to 2.6.27 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References