CVE-2026-74302: Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcicore: Fix UAF in hciunregisterdev()
hciunregisterdev() does not disable cmdtimer and ncmdtimer before the hcidev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free.
Add disabledelayedworksync() calls alongside the existing disableworksync() calls to ensure both timers are fully quiesced before teardown proceeds.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In hci_unregister_dev(), add disable_delayed_work_sync() calls alongside existing disable_work_sync() calls, and ensure both cmd_timer and ncmd_timer are disabled/quiesced before teardown proceeds so callbacks cannot dereference freed memory (fix UAF).
Linux kernel Bluetooth (hci_core) disable_delayed_work_sync() and disable_work_sync() usage during device teardown (hci_unregister_dev) = Add disable_delayed_work_sync() calls alongside existing disable_work_sync() calls; ensure cmd_timer and ncmd_timer are fully quiesced before freeing hci_dev