CVE-2026-68389: Bluetooth: hci_qca: Clear memdump state on invalid dump size
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hciqca: Clear memdump state on invalid dump size
qcacontrollermemdump() allocates qca->qcamemdump before processing the first dump packet. For a sequence-zero packet it then disables IBS, marks memdump collection active, and reads the advertised dump size.
If the controller reports a zero dump size, the error path frees the local qcamemdump object and returns without clearing qca->qcamemdump or undoing the collection state. A later memdump work item initializes its local pointer from qca->qcamemdump and skips allocation when that pointer is non-NULL, so it can operate on freed memory. The stale collection and IBS-disabled flags can also leave waiters or later transmit handling blocked behind an aborted dump.
Clear the saved pointer and memdump state before returning from the invalid-size path, matching the cleanup used when hcidevcdinit() fails.
A static analysis checker reported the stale memdump state, and manual source review confirmed the invalid-size failure path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the hci_qca code so that on the invalid dump size (controller reports zero dump size), the driver clears the saved pointer and the qca->qca_memdump collection/memdump state before returning; ensure cleanup matches the cleanup used when hci_devcd_init() fails (clear qca->qca_memdump local pointer state and undo any IBS-disabled/collection state so waiters are not left blocked and later dump processing cannot operate on freed memory).
Linux kernel Bluetooth driver (hci_qca / qca_controller_memdump) Clear memdump state and saved pointer on invalid dump size = before returning from invalid-size error path
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68389?
CVE-2026-68389 has a risk severity rating of 34.
How do I fix CVE-2026-68389?
To mitigate CVE-2026-68389, upgrade to the latest version of the Linux kernel where the vulnerability has been resolved.
What systems are affected by CVE-2026-68389?
CVE-2026-68389 affects the Linux kernel and its Bluetooth subsystem.
When was CVE-2026-68389 published?
CVE-2026-68389 was published on August 10, 2026.
What is the impact of CVE-2026-68389?
CVE-2026-68389 could potentially lead to security issues related to memory handling in Bluetooth operations.