CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation
Bluetooth: mgmt: fix UAF in pair command cancellation
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.152.1-1 - Compensating control
Mitigate the Bluetooth mgmt UAF by preventing concurrent MGMT_OP_CANCEL_PAIR_DEVICE requests from racing with MGMT_OP_PAIR_DEVICE pairing operations (e.g., serialize management/cancellation operations or rate-limit/cap concurrent cancel requests).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74510?
CVE-2026-74510 has a risk rating of 45.
How do I fix CVE-2026-74510?
To address CVE-2026-74510, ensure you update to a patched version of the Linux Kernel that includes the fix for the use after free vulnerability.
What type of vulnerability is CVE-2026-74510?
CVE-2026-74510 is classified as a Use After Free vulnerability in the Bluetooth management commands of the Linux kernel.
What is affected by CVE-2026-74510?
CVE-2026-74510 affects the Bluetooth management command handling in the Linux Kernel.
When was CVE-2026-74510 published?
CVE-2026-74510 was published on August 15, 2026.