CVE-2026-98295 PUBLISHED

Bluetooth: coredump: Quiesce dump work on unregister

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9695ef876fd122cb7bbc04a4a93b8727d2e36bda to 24af375d7d8aa5f698e4dc41317102f44114351a (excl.)
  • affected from 9695ef876fd122cb7bbc04a4a93b8727d2e36bda to dcaf10ef27f928568c25de3e9fc242e538de5c67 (excl.)
  • affected from 9695ef876fd122cb7bbc04a4a93b8727d2e36bda to 82699d1b727ba5980b94f1eb8dc3d346f41b7c67 (excl.)
  • affected from 9695ef876fd122cb7bbc04a4a93b8727d2e36bda to d236517c264e41dc09833c708ef23bccb7a91219 (excl.)
  • Version deb8156ebe5cb63a5988e7f86cc46aa062527c2b is affected
  • affected from 6.1.188 to 6.2 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.4 is affected
  • unaffected from 0 to 6.4 (excl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References