CVE-2026-68392
Last modified
CVE-2026-68392 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU to ensure the conn is fully initialized at this point..
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU to ensure the conn is fully initialized at this point.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c, < 8bc83f9ef6789571f399ff631a2a14a12b6d8585; >= 227a0cdf4a028a73dc256d0f5144b4808d718893, < 579faba5ede6df6b7f36777c431dc8dcf9d272e7; >= 227a0cdf4a028a73dc256d0f5144b4808d718893, < ca58ad287bfc5b9d31a72ecb8650289df2b57250; >= 227a0cdf4a028a73dc256d0f5144b4808d718893, < b11511006f9e17000de3f4cadee451364f658ca3; >= 227a0cdf4a028a73dc256d0f5144b4808d718893, < 16cd66443957e4ad42155c6fec401012f600c6f8; 58afdc9b18871eb1d461c725be9e9f3f44a39aeb; >= 6.6.51, < 6.6.148; >= 6.10.10, < 6.11 |
| Linux | Linux | 6.11 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68392?
How severe is CVE-2026-68392?
How do I fix CVE-2026-68392?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68387In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68388In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68389In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6839Improper validation of STRING tensor offsets could allows ma…6.6
- CVE-2026-68390In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68391In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68393In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68394In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68395In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68396In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68397In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68398In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
