CVE-2026-98295

high

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: coredump: Quiesce dump work on unregister hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it. Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.

References

https://git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67

https://git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219

https://git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67

https://git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93280

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00175