CVE-2026-74540 is a vulnerability in Linux Kernel
Published on August 15, 2026
Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
l2cap_le_connect_rsp() obtains a channel via
__l2cap_get_chan_by_ident() but neither holds a reference nor uses
l2cap_chan_hold_unless_zero() before locking and operating on it.
A concurrent l2cap_chan_del() triggered by a remote disconnect can
free the channel between the lookup and l2cap_chan_lock(), causing
a use-after-free.
The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler
l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero()
to safely hold a reference, but l2cap_le_connect_rsp() was left
unprotected.
Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup
and l2cap_chan_put() on the exit path, consistent with other L2CAP
response handlers.
Products Associated with CVE-2026-74540
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version f1496dee9cbde2a62821f4441dadb0d3360f60c3 and below fd4c1e301bdec60a40728ea37de531cbccda501a is affected.
- Version f1496dee9cbde2a62821f4441dadb0d3360f60c3 and below 522b730c62c53a1981604fd73524697fd347830d is affected.
- Version f1496dee9cbde2a62821f4441dadb0d3360f60c3 and below 58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136 is affected.
- Version f1496dee9cbde2a62821f4441dadb0d3360f60c3 and below 09f447accc2570751e7d17f0dc0788b40d3edade is affected.
- Version f1496dee9cbde2a62821f4441dadb0d3360f60c3 and below c4740e7f23ff9a8210198d8b4703259e21b9f69d is affected.
- Version 3.14 is affected.
- Before 3.14 is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.