Answer in brief
CVE-2026-98295 records a Unknown severity vulnerability in Bluetooth: coredump: Quiesce dump work on unregister. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9695ef876fd122cb7bbc04a4a93b8727d2e36bda <24af375d7d8aa5f698e4dc41317102f44114351a || >=9695ef876fd122cb7bbc04a4a93b8727d2e36bda <dcaf10ef27f928568c25de3e9fc242e538de5c67 || >=9695ef876fd122cb7bbc04a4a93b8727d2e36bda <82699d1b727ba5980b94f1eb8dc3d346f41b7c67 || >=9695ef876fd122cb7bbc04a4a93b8727d2e36bda <d236517c264e41dc09833c708ef23bccb7a91219 || deb8156ebe5cb63a5988e7f86cc46aa062527c2b || >=6.1.188 <6.2 | 24af375d7d8aa5f698e4dc41317102f44114351a, dcaf10ef27f928568c25de3e9fc242e538de5c67, 82699d1b727ba5980b94f1eb8dc3d346f41b7c67, d236517c264e41dc09833c708ef23bccb7a91219, 6.2 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: coredump: Quiesce dump work on unregister hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it. Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.
Quoted source text, attributed separately from HOL analysis.