KernelScan.io

HIGH Introduced in 3.17

bluetooth HciConnRequest UAF

CVE-2026-53072

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assumes it is held, and if conn is deleted concurrently -> UAF. Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen, and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred listening socket code paths, hci_connect_cfm(conn) is called with hdev->lock held. Fix by holding the lock.

02

Engine v0.3.0

Risk summary

A use-after-free vulnerability exists in the Linux kernel Bluetooth subsystem when handling incoming SCO connection requests with the HCI_PROTO_DEFER flag set. A nearby Bluetooth attacker can trigger a concurrent connection deletion while hci_connect_cfm() operates without the required hdev->lock, potentially leading to memory corruption, information disclosure, or system crash. Exploitation requires a Bluetooth-capable attacker within radio range and a target device with a listening SCO socket using deferred setup.

Affectednet/bluetooth/hci_event.c (Bluetooth HCI event handling)

Vulnerability analysis

The root cause is a missing lock in hci_conn_request_evt() in net/bluetooth/hci_event.c. When the HCI_PROTO_DEFER flag is set (used by SCO for deferred connection setup), the code path called hci_connect_cfm(conn, 0) after an early hci_dev_unlock(hdev), meaning the call occurred without hdev->lock held. Since hci_connect_cfm() assumes the lock is held, a concurrent thread could delete the conn object between the unlock and the use, resulting in a use-after-free. The fix removes the premature hci_dev_unlock() call and the early return, ensuring hci_connect_cfm() is always called with hdev->lock held, consistent with all other non-deferred code paths. The attack surface requires an adjacent Bluetooth attacker to initiate an incoming SCO connection to a device with a listening deferred-setup SCO socket, and relies on a race condition with concurrent connection teardown.

03

BranchIntroducedFixed inPatch commit
5.103.175.10.25860e3f4ff02d1
5.153.175.15.2099d4a6c0f43fc
6.63.176.6.1416b4d226d01ab
6.123.176.12.91541d5bf9b5af
6.183.176.18.33385b2d0468a0
mainline3.177.15c7209a341ff
7.03.177.0.10c27224daf0b0
6.13.176.1.175c7777f534a80