← All Advisories

CVE-2026-97908

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97908

Key Details

CVECVE-2026-97908
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev

The command and ACL RPMsg endpoints store struct btqcomsmd as their

callback private data. The receive callbacks dereference btq->hdev

without taking an hci_dev reference.

The current teardown order frees the hci_dev before destroying the RPMsg

endpoints in both the hci_register_dev() error path and the driver remove

path. If WCNSS delivers data in that window, the endpoint callback can

run with an already freed hci_dev and pass it to the Bluetooth core.

For qcom_smd endpoints, rpmsg_destroy_ept() closes the channel and clears

the callback under the channel recv_lock. The receive path holds the same

lock while invoking the callback, so destroying the endpoints first both

prevents new callbacks and serializes with any callback already running.

Destroy the command and ACL endpoints before hci_free_dev(). Keep

hci_unregister_dev() first during remove so the HCI core stops issuing

operations before the transport endpoints are shut down. In the full

registration-error cleanup path, return directly after freeing the hci_dev

to avoid falling through to the partial-construction labels and destroying

the endpoints twice. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97908
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97908