CVE-2026-63974 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.
A vulnerability in the Linux kernel's Bluetooth subsystem has been addressed. The issue involved the HCI (Host Controller Interface) synchronization process, specifically during the closing of Bluetooth devices. The vulnerability could lead to queuing timeouts while the device's workqueue was being drained. This issue was resolved by ensuring that the HCI_CMD_DRAIN_WORKQUEUE command was set during the device closure process, particularly since the closure can now occur during the reset phase.
The vulnerability has been fixed in the Linux kernel stable tree. Users can upgrade to the latest version available in this repository to address the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |