CVE-2026-68392 is a vulnerability in Linux Kernel
Published on August 10, 2026
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.
Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU
to ensure the conn is fully initialized at this point.
Products Associated with CVE-2026-68392
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c and below 8bc83f9ef6789571f399ff631a2a14a12b6d8585 is affected.
- Version 227a0cdf4a028a73dc256d0f5144b4808d718893 and below 579faba5ede6df6b7f36777c431dc8dcf9d272e7 is affected.
- Version 227a0cdf4a028a73dc256d0f5144b4808d718893 and below ca58ad287bfc5b9d31a72ecb8650289df2b57250 is affected.
- Version 227a0cdf4a028a73dc256d0f5144b4808d718893 and below b11511006f9e17000de3f4cadee451364f658ca3 is affected.
- Version 227a0cdf4a028a73dc256d0f5144b4808d718893 and below 16cd66443957e4ad42155c6fec401012f600c6f8 is affected.
- Version 58afdc9b18871eb1d461c725be9e9f3f44a39aeb is affected.
- Version 6.6.51 and below 6.6.148 is affected.
- Version 6.10.10 and below 6.11 is affected.
- Version 6.11 is affected.
- Before 6.11 is unaffected.
- Version 6.6.148, <= 6.6.* is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.