Answer in brief
CVE-2026-64406 records a Unknown severity vulnerability in Bluetooth: fix UAF in bt_accept_dequeue(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64406 records a Unknown severity vulnerability in Bluetooth: fix UAF in bt_accept_dequeue(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=751de6ec671fe75ad9cf65a0638d2a06b6a5984d <c0577c55219be42b6ea2ea8db11e85bfab6f4e8d || >=407217734835d21d4e0105ebf347860dc1806f88 <96ad400d5132eb333f28f6f1e2d58f0728ca9547 || >=7eebd4c2c86f573af87ff165d08a83432eb0b919 <0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0 || >=5d86d2f1b4d9a508c441d3e45277ae1a73cfed57 <c66a95e60b65d876a927123b0ed36bd6177d9ca6 || >=87c543e2f78d0871f271df92dab98901bbd5b6f5 <6303ed4bbe0095f4cc195225479bf506e010d1db || >=added1213395071470a900cc845a042fb51882a6 <26168db1ce5a9766cde021b18e590a101c056614 || >=ab1513597c6cf17cd1ad2a21e3b045421b48e022 <50c662bdcd51b03033a0abed6716bfd377ba1049 || >=ab1513597c6cf17cd1ad2a21e3b045421b48e022 <4bd0b274054f2679f28b70222b607bb0afc3ab9a || a5ca86a6097a8b030ca3226cd300b17ed330f966 || >=5.10.259 <5.10.261 || >=5.15.210 <5.15.212 || >=6.1.175 <6.1.178 || >=6.6.142 <6.6.145 || >=6.12.92 <6.12.96 || >=6.18.34 <6.18.39 || >=7.0.11 <7.1 | c0577c55219be42b6ea2ea8db11e85bfab6f4e8d, 96ad400d5132eb333f28f6f1e2d58f0728ca9547, 0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0, c66a95e60b65d876a927123b0ed36bd6177d9ca6, 6303ed4bbe0095f4cc195225479bf506e010d1db, 26168db1ce5a9766cde021b18e590a101c056614, 50c662bdcd51b03033a0abed6716bfd377ba1049, 4bd0b274054f2679f28b70222b607bb0afc3ab9a, 5.10.261, 5.15.212, 6.1.178, 6.6.145, 6.12.96, 6.18.39, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=751de6ec671fe75ad9cf65a0638d2a06b6a5984d <c0577c55219be42b6ea2ea8db11e85bfab6f4e8d || >=407217734835d21d4e0105ebf347860dc1806f88 <96ad400d5132eb333f28f6f1e2d58f0728ca9547 || >=7eebd4c2c86f573af87ff165d08a83432eb0b919 <0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0 || >=5d86d2f1b4d9a508c441d3e45277ae1a73cfed57 <c66a95e60b65d876a927123b0ed36bd6177d9ca6 || >=87c543e2f78d0871f271df92dab98901bbd5b6f5 <6303ed4bbe0095f4cc195225479bf506e010d1db || >=added1213395071470a900cc845a042fb51882a6 <26168db1ce5a9766cde021b18e590a101c056614 || >=ab1513597c6cf17cd1ad2a21e3b045421b48e022 <50c662bdcd51b03033a0abed6716bfd377ba1049 || >=ab1513597c6cf17cd1ad2a21e3b045421b48e022 <4bd0b274054f2679f28b70222b607bb0afc3ab9a || a5ca86a6097a8b030ca3226cd300b17ed330f966 || >=5.10.259 <5.10.261 || >=5.15.210 <5.15.212 || >=6.1.175 <6.1.178 || >=6.6.142 <6.6.145 || >=6.12.92 <6.12.96 || >=6.18.34 <6.18.39 || >=7.0.11 <7.1 | c0577c55219be42b6ea2ea8db11e85bfab6f4e8d, 96ad400d5132eb333f28f6f1e2d58f0728ca9547, 0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0, c66a95e60b65d876a927123b0ed36bd6177d9ca6, 6303ed4bbe0095f4cc195225479bf506e010d1db, 26168db1ce5a9766cde021b18e590a101c056614, 50c662bdcd51b03033a0abed6716bfd377ba1049, 4bd0b274054f2679f28b70222b607bb0afc3ab9a, 5.10.261, 5.15.212, 6.1.178, 6.6.145, 6.12.96, 6.18.39, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_accept_unlink(), leaving only the queue reference. bt_accept_unlink() drops the queue reference. The subsequent sock_hold() therefore accesses freed memory if it was the final reference, as observed by KASAN during listening L2CAP socket cleanup. Retain the temporary queue-walk reference through unlink and hand it to the caller on success. Drop it explicitly on the closed and not-yet-connected paths.
Quoted source text, attributed separately from HOL analysis.