Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup critical sections Using RCU-protected pointers outside the critical sections without refcount is incorrect and may result to UAF. Extend critical section to cover both hci_conn_hash lookup and use of the returned conn. Add surrounding rcu_read_lock() also when return value is not used, in preparation for RCU lockdep requirement to hci_lookup_le_connect(). This avoids concurrent deletion of the conn before we are done dereferencing it. Also, make sure to hold hdev->lock when accessing hdev->accept_list.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/38326774df6198df0cc2744cc73bf77cb741c538
- https://git.kernel.org/stable/c/83b7e67698d0b93f685875ce82c8d335436834f7
- https://git.kernel.org/stable/c/d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d
FAQ
What is CVE-2026-68393?
CVE-2026-68393 is a vulnerability with a CVSS score of 8.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup critical sections Using RCU-protected pointers outside the critical sections without ...
How severe is CVE-2026-68393?
CVE-2026-68393 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-68393?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.