KernelScan.io

HIGH Introduced in 6.6

hci_qca Memdump UAF

CVE-2026-68389

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_memdump() allocates qca->qca_memdump before processing the first dump packet. For a sequence-zero packet it then disables IBS, marks memdump collection active, and reads the advertised dump size. If the controller reports a zero dump size, the error path frees the local qca_memdump object and returns without clearing qca->qca_memdump or undoing the collection state. A later memdump work item initializes its local pointer from qca->qca_memdump and skips allocation when that pointer is non-NULL, so it can operate on freed memory. The stale collection and IBS-disabled flags can also leave waiters or later transmit handling blocked behind an aborted dump. Clear the saved pointer and memdump state before returning from the invalid-size path, matching the cleanup used when hci_devcd_init() fails. A static analysis checker reported the stale memdump state, and manual source review confirmed the invalid-size failure path.

02

Engine v0.6.0

Risk summary

A use-after-free in the Qualcomm Bluetooth driver's controller memory dump handler can be triggered by a nearby Bluetooth peer that causes the controller to emit a dump packet with a zero advertised size. The freed buffer is later reused by subsequent dump processing, enabling memory corruption that could lead to code execution or denial of service. Any device with a Qualcomm Bluetooth controller is at risk if an attacker is within Bluetooth range.

Affecteddrivers/bluetooth/hci_qca.c (Bluetooth HCI Qualcomm driver)

Vulnerability analysis

When the Qualcomm Bluetooth controller sends a memory dump packet advertising a zero dump size, the driver's error path frees the dump buffer object but leaves the saved pointer and collection state flags intact. A later dump-processing work item sees the non-NULL stale pointer, skips its own allocation, and operates on the freed memory — a classic use-after-free. The stale flags also keep Bluetooth transmit handling blocked behind an aborted dump. The fix clears the saved pointer, resets the dump state, and re-enables Bluetooth sleep control on the error path, matching the cleanup already used when dump initialization fails. The vulnerable code path is reached when a Bluetooth peer in proximity triggers the controller to generate a debug exception and subsequent memdump with an invalid size; no local account or special privileges are required on the target device, only that a Qualcomm Bluetooth controller is present and active.

03

BranchIntroducedFixed inPatch commit
6.66.66.6.1485a3945e8dea6
6.126.66.12.101069258d5111e
7.16.67.1.62363a7576947
mainline6.67.2-rc4bf587a10c33e
6.186.66.18.42cefb44c367b2