HIGH Introduced in 6.6
hci_qca Memdump UAF
CVE-2026-68389
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_memdump() allocates qca->qca_memdump before processing the first dump packet. For a sequence-zero packet it then disables IBS, marks memdump collection active, and reads the advertised dump size. If the controller reports a zero dump size, the error path frees the local qca_memdump object and returns without clearing qca->qca_memdump or undoing the collection state. A later memdump work item initializes its local pointer from qca->qca_memdump and skips allocation when that pointer is non-NULL, so it can operate on freed memory. The stale collection and IBS-disabled flags can also leave waiters or later transmit handling blocked behind an aborted dump. Clear the saved pointer and memdump state before returning from the invalid-size path, matching the cleanup used when hci_devcd_init() fails. A static analysis checker reported the stale memdump state, and manual source review confirmed the invalid-size failure path.
02KernelScan AI Analysis
Risk summary
A use-after-free in the Qualcomm Bluetooth driver's controller memory dump handler can be triggered by a nearby Bluetooth peer that causes the controller to emit a dump packet with a zero advertised size. The freed buffer is later reused by subsequent dump processing, enabling memory corruption that could lead to code execution or denial of service. Any device with a Qualcomm Bluetooth controller is at risk if an attacker is within Bluetooth range.
Vulnerability analysis
When the Qualcomm Bluetooth controller sends a memory dump packet advertising a zero dump size, the driver's error path frees the dump buffer object but leaves the saved pointer and collection state flags intact. A later dump-processing work item sees the non-NULL stale pointer, skips its own allocation, and operates on the freed memory — a classic use-after-free. The stale flags also keep Bluetooth transmit handling blocked behind an aborted dump. The fix clears the saved pointer, resets the dump state, and re-enables Bluetooth sleep control on the error path, matching the cleanup already used when dump initialization fails. The vulnerable code path is reached when a Bluetooth peer in proximity triggers the controller to generate a debug exception and subsequent memdump with an invalid size; no local account or special privileges are required on the target device, only that a Qualcomm Bluetooth controller is present and active.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 6.6 | 6.6.148 | 5a3945e8dea6 |
| 6.12 | 6.6 | 6.12.101 | 069258d5111e |
| 7.1 | 6.6 | 7.1.6 | 2363a7576947 |
| mainline | 6.6 | 7.2-rc4 | bf587a10c33e |
| 6.18 | 6.6 | 6.18.42 | cefb44c367b2 |