CVE-2026-64406: Bluetooth: fix UAF in bt_accept_dequeue()
Published Jul 25, 2026
·Updated
Bluetooth: fix UAF in btacceptdequeue()
Affected Software
2 affected componentsFixes available
Linux kernel Bluetooth
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1
Event History
Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverity
Data Sourced
via NVD·10:17 AM
DescriptionSeverity
Jul 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64406?
The severity of CVE-2026-64406 is high with a CVSS score of 8.
2
How do I fix CVE-2026-64406?
To fix CVE-2026-64406, update your Linux kernel to the latest version that includes the patch addressing the use-after-free vulnerability.
3
What type of vulnerability is CVE-2026-64406?
CVE-2026-64406 is a use-after-free (UAF) vulnerability in the Bluetooth component of the Linux kernel.
4
What components are affected by CVE-2026-64406?
CVE-2026-64406 affects the Bluetooth subsystem in the Linux kernel.
5
When was CVE-2026-64406 published?
CVE-2026-64406 was published on July 25, 2026.