← All Advisories

CVE-2026-97977

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97977

Key Details

CVECVE-2026-97977
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: Fix UAF of btusb_data by rx_work

btusb_close() and btusb_flush() cancel data->rx_work with the

asynchronous cancel_delayed_work(), so if btusb_rx_work() is already

running on another CPU it keeps running after the cancel returns.

btusb_disconnect() calls hci_unregister_dev(), which invokes

btusb_close(), and then frees the btusb_data. A still running

btusb_rx_work() then dereferences the freed data:

while ((skb = skb_dequeue(&data->acl_q)))

data->recv_acl(data->hdev, skb);

Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also

has to happen after btusb_stop_traffic(), otherwise an URB completion

racing with the cancel can requeue the work right after it has been

waited for. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97977
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97977