Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
Published: 2026-10-06
Score: 7.0 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Sun, 11 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Wed, 07 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Tue, 06 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 06 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: coredump: Quiesce dump work on unregister hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it. Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.
Title Bluetooth: coredump: Quiesce dump work on unregister
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:45:54.141Z

Reserved: 2026-09-25T10:25:14.337Z

Link: CVE-2026-98295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:20.133

Modified: 2026-10-06T09:18:20.133

Link: CVE-2026-98295

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-06T00:00:00Z

Links: CVE-2026-98295 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T18:45:19Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference