CVE-2026-74529 is a vulnerability in Linux Kernel
Published on August 15, 2026
Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
There is theoretical UAF if the conn is freed while the hci_sync task is
running.
Hold refcount to avoid that.
Products Associated with CVE-2026-74529
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 6d0417e4e1cf66fd917f06f0454958362714ef7d and below c53c70ec289ee12f20c4f1b2fbfd151762c01f67 is affected.
- Version 6d0417e4e1cf66fd917f06f0454958362714ef7d and below 44fc74069d8988f2825246f9401218e29de2c0ab is affected.
- Version eb8b860e87b296bd1874c79a668081efd00f9754 is affected.
- Version 94bf6380e936339a700c0b3171a49baf512aa70b is affected.
- Version 6.12.28 and below 6.13 is affected.
- Version 6.14.6 and below 6.15 is affected.
- Version 6.15 is affected.
- Before 6.15 is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.