CVE-2026-63974

HIGHCVSS 8.8/10EPSS 0.32%

Last modified

CVE-2026-63974 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.32%

24.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < 9cebe4680bb9a72f80c6541eb24af06db7a1fbc9; >= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < 47330cc875b36a1cf7b3543cb2cf90a7c603ce0e; >= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < 60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff; >= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < 525daaea459fc215f432de1b8debbd9144bf97b0; 4bf367fa1fefabdf14938d0ac9ed60020389112e; 3b382555706558f5c0587862b6dc03e96a252bba; >= 5.18.18, < 5.19; >= 5.19.2, < 5.20
LinuxLinux6.0

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63974?
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.
How severe is CVE-2026-63974?
CVE-2026-63974 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63974?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63974?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST