Answer in brief
CVE-2026-68085 records a Unknown severity vulnerability in Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=81c7a3c22a0f2808cf4ae0b4908f59763b23606d <d52446b3e735cfdbdc2a58342163803bc2e64249 || >=192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894 <b9dd39cf1667e378b25a082ca796d495d578c5d3 || >=c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b <714d861d35d937f23375a4517569b13917bbbe51 || >=c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b <1b0d946d6f08bd39211385bc703a440911b41e46 || 78aad93e938f013d9272fe0ee168f27883afa95c || e2d19969c8d9198ecc3090bcd5312ecd503a3339 || c85cff648a2bc92322912db5f1727ad05afae7b6 || 9d20d48be2c4a071fb015eb09bda2cecd25daf34 || 7338031946bd06f6dff149e67b60c4cd083bfea8 || >=6.12.92 <6.12.96 || >=6.18.34 <6.18.39 || >=5.10.258 <5.11 || >=5.15.209 <5.16 || >=6.1.175 <6.2 || >=6.6.142 <6.7 || >=7.0.11 <7.1 | d52446b3e735cfdbdc2a58342163803bc2e64249, b9dd39cf1667e378b25a082ca796d495d578c5d3, 714d861d35d937f23375a4517569b13917bbbe51, 1b0d946d6f08bd39211385bc703a440911b41e46, 6.12.96, 6.18.39, 5.11, 5.16, 6.2, 6.7, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is pending and blocks queueing it again. Currently this bit is not cleared when canceling the work in hci_uart_close(), which blocks future writes when device is reopened later if write_work was pending. Fix by clearing HCI_UART_SENDING when canceling the work. Also make clearing of tx_skb safe by using disable_work_sync + enable_work instead of just cancel_work_sync. hci_uart_flush() purges the proto tx queue so we can cancel the pending write_work there, instead of doing it just in hci_uart_close(). Re-enable and possibly requeue the work after queue flush.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68085 records a Unknown severity vulnerability in Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=81c7a3c22a0f2808cf4ae0b4908f59763b23606d <d52446b3e735cfdbdc2a58342163803bc2e64249 || >=192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894 <b9dd39cf1667e378b25a082ca796d495d578c5d3 || >=c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b <714d861d35d937f23375a4517569b13917bbbe51 || >=c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b <1b0d946d6f08bd39211385bc703a440911b41e46 || 78aad93e938f013d9272fe0ee168f27883afa95c || e2d19969c8d9198ecc3090bcd5312ecd503a3339 || c85cff648a2bc92322912db5f1727ad05afae7b6 || 9d20d48be2c4a071fb015eb09bda2cecd25daf34 || 7338031946bd06f6dff149e67b60c4cd083bfea8 || >=6.12.92 <6.12.96 || >=6.18.34 <6.18.39 || >=5.10.258 <5.11 || >=5.15.209 <5.16 || >=6.1.175 <6.2 || >=6.6.142 <6.7 || >=7.0.11 <7.1 | d52446b3e735cfdbdc2a58342163803bc2e64249, b9dd39cf1667e378b25a082ca796d495d578c5d3, 714d861d35d937f23375a4517569b13917bbbe51, 1b0d946d6f08bd39211385bc703a440911b41e46, 6.12.96, 6.18.39, 5.11, 5.16, 6.2, 6.7, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is pending and blocks queueing it again. Currently this bit is not cleared when canceling the work in hci_uart_close(), which blocks future writes when device is reopened later if write_work was pending. Fix by clearing HCI_UART_SENDING when canceling the work. Also make clearing of tx_skb safe by using disable_work_sync + enable_work instead of just cancel_work_sync. hci_uart_flush() purges the proto tx queue so we can cancel the pending write_work there, instead of doing it just in hci_uart_close(). Re-enable and possibly requeue the work after queue flush.
Quoted source text, attributed separately from HOL analysis.