CVE-2026-64433: Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
Published Jul 25, 2026
·Updated
Bluetooth: MGMT: Fix UAF of hciconnparams in adddevicecomplete
Affected Software
2 affected componentsFixes available
Linux Linux kernel=7.0.11
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1
Event History
Jul 25, 2026
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
Description
Data Sourced
via NVD·10:17 AM
Description
Jul 26, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64433?
CVE-2026-64433 has a medium severity score of 5.5.
2
How do I fix CVE-2026-64433?
To fix CVE-2026-64433, update to the latest Linux kernel version where this vulnerability has been patched.
3
What type of vulnerability is CVE-2026-64433?
CVE-2026-64433 is classified as a Use After Free vulnerability.
4
Which systems are affected by CVE-2026-64433?
CVE-2026-64433 affects the Linux kernel and Microsoft azl3 kernel 6.6.144.1-1.
5
What does CVE-2026-64433 involve?
CVE-2026-64433 involves a use-after-free vulnerability in the hci_conn_params during the add_device_complete function in the Bluetooth management.