CVE-2026-64471

Unknown

Last modified

CVE-2026-64471 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on registration failure Make sure to release the sibling interfaces in case controller registration fails to avoid use-after-free and double-free when they are eventually disconnected. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths..

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on registration failure Make sure to release the sibling interfaces in case controller registration fails to avoid use-after-free and double-free when they are eventually disconnected. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < e09ac7d0c6859a360bf36e7104aef03f88184e0b; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < 468fcdfaeb937163dd250773a9fed17ab1fa203c; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < 1ce5012944afaddbda939ec6bae9800fce84abbc; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < e6313b800da61a26c2fdd5eba0105e197c0ab3bc; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < 14e02f1449ba425a44dedbec9a21efafb056e09f; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < 8db0ce3de78367f61c2970c0f16d9adee8830a23; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < da7d7758fe884b256ddc9fef562e5ddef7952383; >= 9bfa35fe422c74882e27cc54450a5f76c96aad68, < eedc6867ebad73edbfaf9a0a65fbef7115cc4753
LinuxLinux2.6.27

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-64471?
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on registration failure Make sure to release the sibling interfaces in case controller registration fails to avoid use-after-free and double-free when they are eventually disconnected. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.
How severe is CVE-2026-64471?
Severity scoring for CVE-2026-64471 is pending analysis.
How do I fix CVE-2026-64471?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64471?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST