CVE-2026-98294: Bluetooth: hci_qca: Do not write to the serial port after it is closed

Published Oct 6, 2026
·
Updated

Bluetooth: hciqca: Do not write to the serial port after it is closed

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the Linux kernel Bluetooth hci_qca path, check HCI_UART_PROTO_READY before qca_power_off() writes to the serial port, because hci_uart_close() clears this flag when the port is closed.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are most likely to be affected?

The issue applies to Linux systems using the hci_qca Bluetooth driver with HCI_QUIRK_NON_PERSISTENT_SETUP, such as the WCN399x family. It was observed specifically on WCN3988 hardware.

2

What conditions are needed to trigger the failure?

A successful qca_setup() must be followed by a failed hci_dev_open_sync(), leaving power->vregs_on set while the serdev port has been closed. Unbinding the driver after that controller failure can then cause the remove path to write to the closed port.

3

How can I recognize that this issue has occurred?

The reported symptom is a kernel NULL pointer dereference during driver removal. The call trace can include tty_set_termios, ttyport_set_baudrate, serdev_device_set_baudrate, qca_power_shutdown or qca_power_off, and qca_serdev_remove.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203