CVE-2026-74528: Bluetooth: hci_sync: hold conn in hci_past_sync() callback
Published Aug 15, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisync: hold conn in hcipastsync() callback
Avoids giving freed pointers to hciconnvalid(), which kmalloc may have reused.
Hold refcount to avoid that.
Event History
Aug 15, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-74528?
The severity of CVE-2026-74528 is rated as 30.
2
How do I fix CVE-2026-74528?
To fix CVE-2026-74528, update your Linux kernel to the latest version where the vulnerability has been resolved.
3
What types of systems are affected by CVE-2026-74528?
CVE-2026-74528 affects systems using the Linux kernel with Bluetooth functionality.
4
What impact does CVE-2026-74528 have on system security?
CVE-2026-74528 could potentially lead to instability by causing freed pointers to be accessed, which may increase the risk of system crashes.
5
When was CVE-2026-74528 published?
CVE-2026-74528 was published on August 15, 2026.