CVE-2026-98294: Bluetooth: hci_qca: Do not write to the serial port after it is closed
Bluetooth: hciqca: Do not write to the serial port after it is closed
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the Linux kernel Bluetooth hci_qca path, check HCI_UART_PROTO_READY before qca_power_off() writes to the serial port, because hci_uart_close() clears this flag when the port is closed.
Event History
Frequently Asked Questions
Which systems are most likely to be affected?
The issue applies to Linux systems using the hci_qca Bluetooth driver with HCI_QUIRK_NON_PERSISTENT_SETUP, such as the WCN399x family. It was observed specifically on WCN3988 hardware.
What conditions are needed to trigger the failure?
A successful qca_setup() must be followed by a failed hci_dev_open_sync(), leaving power->vregs_on set while the serdev port has been closed. Unbinding the driver after that controller failure can then cause the remove path to write to the closed port.
How can I recognize that this issue has occurred?
The reported symptom is a kernel NULL pointer dereference during driver removal. The call trace can include tty_set_termios, ttyport_set_baudrate, serdev_device_set_baudrate, qca_power_shutdown or qca_power_off, and qca_serdev_remove.