CVE-2026-74530 is a vulnerability in Linux Kernel
Published on August 15, 2026
Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
There is theoretical UAF if the conn is freed while the hci_sync task is
running.
Hold refcount to avoid that. Handle NULL hcon, return 0 + do nothing to
match the previous behavior.
Products Associated with CVE-2026-74530
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 024421cf39923927ab2b5fe895d1d922b9abe67f and below 2d91e6244b69d752503b2d44020d8b0e323dbd38 is affected.
- Version 024421cf39923927ab2b5fe895d1d922b9abe67f and below 56e78b670356caab0b607e8aad4cf819a1909d07 is affected.
- Version 620810ac1f7f1133a9ac403e132b3ad6995ddf39 is affected.
- Version ee0586ad64a805eaf1a9a10100e908627a561e34 is affected.
- Version 6.12.28 and below 6.13 is affected.
- Version 6.14.6 and below 6.15 is affected.
- Version 6.15 is affected.
- Before 6.15 is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.