CVE-2026-53073 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to NULL. This means incoming UART data will reach the protocol-specific recv handler in hci_uart_tty_receive() after resources are freed. Clear HCI_UART_PROTO_INIT with a write lock before calling hu->proto->close() and setting hu->hdev to NULL. The write lock ensures all active readers have completed and no new reader can enter the protocol recv path before resources are freed. This allows the protocol-specific recv functions to remove the "HCI_UART_REGISTERED" guard without risking a null pointer dereference if hci_register_dev() fails.
A vulnerability in the Linux kernel's Bluetooth subsystem has been addressed. When the function hci_register_dev() fails during the initialization of a Bluetooth UART device, the HCI_UART_PROTO_INIT flag is not cleared before the device's protocol handler is closed and the device is set to NULL. This oversight can lead to a situation where incoming UART data is processed by a handler that has already released its resources. The vulnerability arises because the protocol-specific receive functions can be called after the resources have been freed, potentially leading to a null pointer dereference. The issue has been fixed by ensuring that the HCI_UART_PROTO_INIT flag is cleared with a write lock before closing the protocol handler and nullifying the device reference. This change prevents data from being sent to a handler that is no longer valid, thereby eliminating the risk of a null pointer dereference.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version of the stable Linux kernel where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/194f029a4d7f739e44ebc1f473120187b4de5104 | kernel.org | Patch |
| https://git.kernel.org/stable/c/356dee1bcac4d0d9152390561fa63331ebff211b | kernel.org | Patch |
| https://git.kernel.org/stable/c/3daa5818e473ed60eb69d8b5c71b651909d28c5a | kernel.org | Patch |
| https://git.kernel.org/stable/c/68d39ea5e0adc9ecaea1ce8abd842ec972eb8718 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a673cf6c4ac702cb79ac1f4d7fc4de763a6a3e40 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ebb39b2d81731b83ee71a1ba6dd0291a57b5ac07 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ed4033fb85ccaaf6c3983be3c7b037e48253d232 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f4b69c35813c432973d340d3600c01de106ed474 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.4.293, < 5.5 >= 5.10.237, < 5.10.258 >= 5.15.181, < 5.15.209 >= 6.1.135, < 6.1.175 >= 6.6.88, < 6.6.141 >= 6.12.24, < 6.12.91 >= 6.13.12, < 6.14 >= 6.14.3, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |