In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
There is theoretical UAF if the conn is freed while the hci_sync task
is running.
Hold refcount to avoid that.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 08:16
Updated : 2026-08-29 07:16
NVD link : CVE-2026-80692
Mitre link : CVE-2026-80692
CVE.ORG link : CVE-2026-80692
JSON object : View
Products Affected
No product.
CWE
No CWE.
