{"id":"CVE-2026-68189","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-68189","summary":"Bluetooth: hci_sync: Protect UUID list traversal","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Protect UUID list traversal\n\nThe hci_sync conversion moved class-of-device and EIR generation from an\nHCI request built under hdev->lock to asynchronous command sync work.\nThe worker holds hdev->req_lock, but that lock does not serialize access\nto hdev->uuids against add_uuid() and remove_uuid(), which update the\nlist under hdev->lock.\n\nThe following interleaving can therefore occur:\n\n  CPU0 (command sync work)       CPU1 (management socket)\n  fetch uuid from the list\n                                list_del(&uuid->list)\n                                kfree(uuid)\n  read uuid->size\n\nKASAN reports the resulting use-after-free:\n\n  BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0\n  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87\n  Workqueue: hci0 hci_cmd_sync_work\n  Call Trace:\n   eir_create+0xb8f/0xee0\n   hci_update_eir_sync+0x1c0/0x330\n   hci_cmd_sync_work+0x13c/0x290\n   process_one_work+0x63a/0x1070\n   worker_thread+0x45b/0xd10\n\n  Allocated by task 86:\n   __kasan_kmalloc+0x8f/0xa0\n   add_uuid+0x18a/0x4b0\n   hci_sock_sendmsg+0x1033/0x1ea0\n\n  Freed by task 92:\n   __kasan_slab_free+0x43/0x70\n   kfree+0x131/0x3c0\n   remove_uuid+0x25e/0x560\n   hci_sock_sendmsg+0x1033/0x1ea0\n\nHold hdev->lock while generating and committing the class-of-device and\nEIR snapshots.  Release it before sending an HCI command, so controller\nwaits do not happen under the device lock.  This protects all UUID list\nwalks in these paths and restores the serialization lost in the command\nsync conversion.","published":"2026-08-10T12:00:01.711Z","modified":"2026-08-14T04:03:55.808039707Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.148"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/a351f68fb24828b23a971e00b8238ee0e8a40380"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a42f5536ea9c00e13f0c0fbb330feed95e2365ca"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e4fa2c5c261d736b8e58759fdef3a968d510630c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e9027ffbf5a0f3c12ca8900822e884eae9f0821b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fe13adc258df88d95789e5673c7ba5178b5f8b28"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68189.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68189"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T04:03:55.808039707Z"}}