CVE-2026-98295
Description
AI Translation Available
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: coredump: Quiesce dump work on unregister
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.
Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
https://git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a
https://git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67
https://git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219
https://git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67