CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix UAF in pair command cancellation
The pairing completion and authentication failure callbacks look up the pending MGMTOPPAIRDEVICE command by walking hdev->mgmtpending. The lookup returned a command that was still linked on the shared pending list, without keeping mgmtpendinglock held for the later dereference and removal.
A concurrent MGMTOPCANCELPAIRDEVICE request can remove and free the same pending command before the callback uses it. The reverse race is also possible when cancelpairdevice() gets a command from pendingfind() and a callback removes it before the cancel path dereferences it. This can lead to a use-after-free and a second listdel().
Make the pairing lookup helpers transfer ownership of the pending command by removing it from hdev->mgmtpending while holding mgmtpendinglock. The callbacks and cancel path then complete the command and free it directly, so racing paths cannot find or free the same command again. Take a temporary hciconn reference in cancelpairdevice() because the command completion drops the reference stored in the pending command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the Bluetooth mgmt UAF by preventing concurrent MGMT_OP_CANCEL_PAIR_DEVICE requests from racing with MGMT_OP_PAIR_DEVICE pairing operations (e.g., serialize management/cancellation operations or rate-limit/cap concurrent cancel requests).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74510?
CVE-2026-74510 has a risk rating of 45.
How do I fix CVE-2026-74510?
To address CVE-2026-74510, ensure you update to a patched version of the Linux Kernel that includes the fix for the use after free vulnerability.
What type of vulnerability is CVE-2026-74510?
CVE-2026-74510 is classified as a Use After Free vulnerability in the Bluetooth management commands of the Linux kernel.
What is affected by CVE-2026-74510?
CVE-2026-74510 affects the Bluetooth management command handling in the Linux Kernel.
When was CVE-2026-74510 published?
CVE-2026-74510 was published on August 15, 2026.