CVE-2026-68390 is a vulnerability in Linux Kernel
Published on August 10, 2026
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
hci_conn_params_lookup requires hdev->lock be held, otherwise the list
iteration or param access is not safe.
Hold hdev->lock for params lookups in hci_sync.
Products Associated with CVE-2026-68390
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version c530569adc19b5f0c62955de41f067bad34e3fe0 and below 8d892bec1dd134761cabec6ba23fe315d0f20f98 is affected.
- Version c530569adc19b5f0c62955de41f067bad34e3fe0 and below c363202ec841df36421ec280eea3d5f94f556143 is affected.
- Version 6.19 is affected.
- Before 6.19 is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.