Answer in brief
CVE-2026-63974 records a Unknown severity vulnerability in Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <9cebe4680bb9a72f80c6541eb24af06db7a1fbc9 || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <47330cc875b36a1cf7b3543cb2cf90a7c603ce0e || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <525daaea459fc215f432de1b8debbd9144bf97b0 || 4bf367fa1fefabdf14938d0ac9ed60020389112e || 3b382555706558f5c0587862b6dc03e96a252bba || >=5.18.18 <5.19 || >=5.19.2 <5.20 | 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9, 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e, 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff, 525daaea459fc215f432de1b8debbd9144bf97b0, 5.19, 5.20 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-63974 records a Unknown severity vulnerability in Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <9cebe4680bb9a72f80c6541eb24af06db7a1fbc9 || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <47330cc875b36a1cf7b3543cb2cf90a7c603ce0e || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff || >=877afadad2dce8aae1f2aad8ce47e072d4f6165e <525daaea459fc215f432de1b8debbd9144bf97b0 || 4bf367fa1fefabdf14938d0ac9ed60020389112e || 3b382555706558f5c0587862b6dc03e96a252bba || >=5.18.18 <5.19 || >=5.19.2 <5.20 | 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9, 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e, 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff, 525daaea459fc215f432de1b8debbd9144bf97b0, 5.19, 5.20 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.
Quoted source text, attributed separately from HOL analysis.