CVE-2026-64406: Bluetooth: fix UAF in bt_accept_dequeue()
Published Jul 25, 2026
·Updated
Bluetooth: fix UAF in btacceptdequeue()
Affected Software
16 affected componentsFixes available
Linux kernel Bluetooth
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Linux Linux kernel>=5.10.259<5.10.261
Linux Linux kernel>=5.15.210<5.15.212
Linux Linux kernel>=6.1.175<6.1.178
Linux Linux kernel>=6.6.142<6.6.145
Linux Linux kernel>=6.12.92<6.12.96
Linux Linux kernel>=6.18.34<6.18.39
Linux Linux kernel>=7.0.11<7.1
Linux Linux kernel>=7.1.1<7.1.4
Linux Linux kernel=7.1
Linux Linux kernel=7.1-rc5
Linux Linux kernel=7.1-rc6
Linux Linux kernel=7.1-rc7
Linux Linux kernel=7.2-rc1
Linux Linux kernel=7.2-rc2
Remediation
Event History
Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverity
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64406?
The severity of CVE-2026-64406 is high with a CVSS score of 8.
2
How do I fix CVE-2026-64406?
To fix CVE-2026-64406, update your Linux kernel to the latest version that includes the patch addressing the use-after-free vulnerability.
3
What type of vulnerability is CVE-2026-64406?
CVE-2026-64406 is a use-after-free (UAF) vulnerability in the Bluetooth component of the Linux kernel.
4
What components are affected by CVE-2026-64406?
CVE-2026-64406 affects the Bluetooth subsystem in the Linux kernel.
5
When was CVE-2026-64406 published?
CVE-2026-64406 was published on July 25, 2026.