CVE-2026-74510
7.8Linux · Kernel
A Use-After-Free (UAF) vulnerability in the Linux kernel Bluetooth management interface occurs during the cancellation of pairing commands.
Executive summary
A Use-After-Free vulnerability within the Linux kernel Bluetooth management subsystem could allow a local attacker to cause system crashes or gain unauthorized control over the kernel.
Vulnerability
The flaw exists in the Bluetooth management code, where pairing completion and failure callbacks improperly handle pending commands, leading to a UAF. This requires an authenticated local user to initiate the attack.
Business impact
With a CVSS score of 7.8, this vulnerability poses a significant risk to systems utilizing Bluetooth functionality. A successful exploit could lead to full system compromise or persistent denial of service, impacting the reliability of critical infrastructure or workstations.
Remediation
Immediate Action: Update the Linux kernel to version 6.6.151, 6.12.103, 6.18.44, or later versions as maintained by your distribution.
Proactive Monitoring: Review kernel logs for Bluetooth subsystem errors or unexpected service restarts, which could serve as indicators of exploitation attempts.
Compensating Controls: Disable Bluetooth services on servers or systems where wireless peripheral connectivity is not strictly required to reduce the attack surface.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
System administrators must ensure kernel updates are applied to all devices running Bluetooth services. Prompt patching is essential to prevent local privilege escalation and maintain the security posture of the host system.