CVE-2026-64408: Bluetooth: bnep: pin L2CAP connection during netdev registration
Bluetooth: bnep: pin L2CAP connection during netdev registration
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Compensating control
In the Bluetooth BNEP connection-registration path, take a reference to the L2CAP connection while holding the channel lock and retain it until register_netdev() has taken the parent device reference, preventing teardown from releasing the connection concurrently.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running an affected Linux kernel or Microsoft azl3 kernel with Bluetooth BNEP functionality in use are exposed during BNEP network-device registration and concurrent controller teardown.
What access does an attacker need to exploit it?
The CVSS vector indicates adjacent-network access is sufficient, with no privileges or user interaction required. Exploitation depends on triggering the Bluetooth BNEP connection and the concurrent teardown race.
What is the impact if exploitation succeeds?
The race can cause the network-device registration path to dereference a freed parent device. The assigned CVSS score is 8.8, with high confidentiality, integrity, and availability impact.
What should be done if patching is not immediately possible?
The provided data does not identify a configuration workaround. Prioritize applying the available patch, particularly on systems where Bluetooth BNEP connections may be established.