CVE-2026-64405: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
Published Jul 25, 2026
·Updated
Bluetooth: hciconn: Fix null ptr deref in hciabortconn()
Affected Software
10 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Linux Linux kernel>=6.1.83<6.1.118
Linux Linux kernel>=6.4.16<6.5
Linux Linux kernel>=6.5.3<6.6.145
Linux Linux kernel>=6.7<6.12.97
Linux Linux kernel>=6.13<6.18.39
Linux Linux kernel>=6.19<7.1.4
Linux Linux kernel=7.2-rc1
Linux Linux kernel=7.2-rc2
Remediation
Event History
Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
Description
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 26, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:05 AM
Affected Software
Updated
via Microsoft·08:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access is required to exploit this issue?
The severity vector indicates local access with low privileges is required. No user interaction is required.
2
What is the likely security impact?
The issue can cause a NULL pointer dereference and general protection fault in the Bluetooth receive work path. The supplied vector rates integrity and availability impact as high, with no confidentiality impact.
3
What should affected administrators do?
Apply an available patch. The provided references include stable kernel commits addressing the issue.