HIGH Introduced in 3.17
bluetooth HciConnRequest UAF
CVE-2026-53072
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assumes it is held, and if conn is deleted concurrently -> UAF. Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen, and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred listening socket code paths, hci_connect_cfm(conn) is called with hdev->lock held. Fix by holding the lock.
02KernelScan AI Analysis
Risk summary
A use-after-free vulnerability exists in the Linux kernel Bluetooth subsystem when handling incoming SCO connection requests with the HCI_PROTO_DEFER flag set. A nearby Bluetooth attacker can trigger a concurrent connection deletion while hci_connect_cfm() operates without the required hdev->lock, potentially leading to memory corruption, information disclosure, or system crash. Exploitation requires a Bluetooth-capable attacker within radio range and a target device with a listening SCO socket using deferred setup.
Vulnerability analysis
The root cause is a missing lock in hci_conn_request_evt() in net/bluetooth/hci_event.c. When the HCI_PROTO_DEFER flag is set (used by SCO for deferred connection setup), the code path called hci_connect_cfm(conn, 0) after an early hci_dev_unlock(hdev), meaning the call occurred without hdev->lock held. Since hci_connect_cfm() assumes the lock is held, a concurrent thread could delete the conn object between the unlock and the use, resulting in a use-after-free. The fix removes the premature hci_dev_unlock() call and the early return, ensuring hci_connect_cfm() is always called with hdev->lock held, consistent with all other non-deferred code paths. The attack surface requires an adjacent Bluetooth attacker to initiate an incoming SCO connection to a device with a listening deferred-setup SCO socket, and relies on a race condition with concurrent connection teardown.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 3.17 | 5.10.258 | 60e3f4ff02d1 |
| 5.15 | 3.17 | 5.15.209 | 9d4a6c0f43fc |
| 6.6 | 3.17 | 6.6.141 | 6b4d226d01ab |
| 6.12 | 3.17 | 6.12.91 | 541d5bf9b5af |
| 6.18 | 3.17 | 6.18.33 | 385b2d0468a0 |
| mainline | 3.17 | 7.1 | 5c7209a341ff |
| 7.0 | 3.17 | 7.0.10 | c27224daf0b0 |
| 6.1 | 3.17 | 6.1.175 | c7777f534a80 |