CVE-2026-97977 PUBLISHED

Bluetooth: btusb: Fix UAF of btusb_data by rx_work

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: Fix UAF of btusb_data by rx_work

btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.

btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data:

<pre>while ((skb = skb_dequeue(&data->acl_q))) data->recv_acl(data->hdev, skb); </pre>

Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 800fe5ec302e1ebbf5e3f891f886deecd49c7132 to 472d005622525b7be155cac99dde2252b0163bd1 (excl.)
  • affected from 800fe5ec302e1ebbf5e3f891f886deecd49c7132 to 93b59937bda3fffc6386c79f5544a39bc680c8e8 (excl.)
  • affected from 800fe5ec302e1ebbf5e3f891f886deecd49c7132 to fa391adb9c755515a89993634745e9079e5ef37c (excl.)
  • affected from 800fe5ec302e1ebbf5e3f891f886deecd49c7132 to 1c12c3117639e78940959d956519c758c57d0849 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.17 is affected
  • unaffected from 0 to 5.17 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References