CVE-2026-46111 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in create_big_sync Add hci_conn_valid() check in create_big_sync() to detect stale connections before proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the connection under hci_dev_lock() before dereferencing, matching the pattern used by create_le_conn_complete() and create_pa_complete(). Keep the hci_conn object alive across the async boundary by taking a reference via hci_conn_get() when queueing create_big_sync(), and dropping it in the completion callback. The refcount and the lock are complementary: the refcount keeps the object allocated, while hci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on hdev->conn_hash, as required by hci_conn_del(). hci_conn_put() is called outside hci_dev_unlock() so the final put (which resolves to kfree() via bt_link_release) does not run under hdev->lock, though the release path would be safe either way. Without this, create_big_complete() would unconditionally dereference the conn pointer on error, causing a use-after-free via hci_connect_cfm() and hci_conn_del().
A use-after-free vulnerability has been addressed in the Bluetooth subsystem of the Linux kernel. The issue was related to the creation of Broadcast Isochronous Groups (BIG) connections. The vulnerability arose because the connection object was not properly validated before being used, leading to the potential for asynchronous operations to dereference a freed object. This could cause memory corruption by accessing invalid memory, which is a common exploitation technique.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0beddb0c380bed5f5b8e61ddbe14635bb73d0b41 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1750a2df0eab61dc421a7afae74abdd239a44b85 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6823f730bf195fc296d9edd09e2ca94bc1ff5584 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d41093723e47255d7d74df86e2736711c1b8486e | kernel.org | |
| https://git.kernel.org/stable/c/dc34f8d8240f25dd137dc2758ebbcc75e3779142 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f8eaf92c57ad99358dd372580d5ff87623343a72 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0, < 6.6.140 >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |