Answer in brief
CVE-2026-74531 records a Unknown severity vulnerability in Bluetooth: hci_conn: hold conn reference in abort_conn_sync(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=249c88e7fb45b6b705040c5af4bd0d0f2bc9735c <64d1645f26aa49b5a86ba2fccd0bb6749ea725a6 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <963fb4b8e7d1ab07b4ae45bf15d41e667c88caca || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <e8f9fef362bab431d95371d3406bc720350290c3 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <fa812cfa81aa3d4a7b6ce8277979af57b3f79712 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <5761d003daa987ac81463f570713ce9c9dd204e5 || 58afdc9b18871eb1d461c725be9e9f3f44a39aeb || >=6.6.51 <6.6.151 || >=6.10.10 <6.11 | 64d1645f26aa49b5a86ba2fccd0bb6749ea725a6, 963fb4b8e7d1ab07b4ae45bf15d41e667c88caca, e8f9fef362bab431d95371d3406bc720350290c3, fa812cfa81aa3d4a7b6ce8277979af57b3f79712, 5761d003daa987ac81463f570713ce9c9dd204e5, 6.6.151, 6.11 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in abort_conn_sync() There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74531 records a Unknown severity vulnerability in Bluetooth: hci_conn: hold conn reference in abort_conn_sync(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=249c88e7fb45b6b705040c5af4bd0d0f2bc9735c <64d1645f26aa49b5a86ba2fccd0bb6749ea725a6 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <963fb4b8e7d1ab07b4ae45bf15d41e667c88caca || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <e8f9fef362bab431d95371d3406bc720350290c3 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <fa812cfa81aa3d4a7b6ce8277979af57b3f79712 || >=227a0cdf4a028a73dc256d0f5144b4808d718893 <5761d003daa987ac81463f570713ce9c9dd204e5 || 58afdc9b18871eb1d461c725be9e9f3f44a39aeb || >=6.6.51 <6.6.151 || >=6.10.10 <6.11 | 64d1645f26aa49b5a86ba2fccd0bb6749ea725a6, 963fb4b8e7d1ab07b4ae45bf15d41e667c88caca, e8f9fef362bab431d95371d3406bc720350290c3, fa812cfa81aa3d4a7b6ce8277979af57b3f79712, 5761d003daa987ac81463f570713ce9c9dd204e5, 6.6.151, 6.11 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in abort_conn_sync() There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.
Quoted source text, attributed separately from HOL analysis.