MEDIUM

CVE-2026-53073

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error

When hci_register_dev() fails in hci_uart_register_dev()
HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu)
and setting hu->hdev to NULL. This means incoming UART data will reach
the protocol-specific recv handler in hci_uart_tty_receive() after
resources are freed.

Clear HCI_UART_PROTO_INIT with a write lock before calling
hu->proto->close() and setting hu->hdev to NULL. The write lock ensures
all active readers have completed and no new reader can enter the
protocol recv path before resources are freed.

This allows the protocol-specific recv functions to remove the
"HCI_UART_REGISTERED" guard without risking a null pointer dereference
if hci_register_dev() fails.

Summary dbcve.org

A race condition in the Linux kernel's Bluetooth HCI UART driver (hci_ldisc) allows incoming UART data to reach the protocol-specific recv handler after resources are freed. When hci_register_dev() fails, the HCI_UART_PROTO_INIT flag is not cleared before calling hu->proto->close() and setting hu->hdev to NULL, allowing freed resources to be accessed.

Mitigation

Apply the kernel patch that adds a write lock to clear HCI_UART_PROTO_INIT before resource cleanup, ensuring all active readers complete and no new reader can enter the protocol recv path.

Patch Commit

Weakness (CWE)

CWE-476 NULL Pointer Dereference

EPSS Score

0.11%
Probability of exploitation in next 30 days
1.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE