CVE-2026-53073
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-476
Desreferencia a puntero nulo (NULL)
Fecha de publicación:
24/06/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error<br />
<br />
When hci_register_dev() fails in hci_uart_register_dev()<br />
HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu)<br />
and setting hu->hdev to NULL. This means incoming UART data will reach<br />
the protocol-specific recv handler in hci_uart_tty_receive() after<br />
resources are freed.<br />
<br />
Clear HCI_UART_PROTO_INIT with a write lock before calling<br />
hu->proto->close() and setting hu->hdev to NULL. The write lock ensures<br />
all active readers have completed and no new reader can enter the<br />
protocol recv path before resources are freed.<br />
<br />
This allows the protocol-specific recv functions to remove the<br />
"HCI_UART_REGISTERED" guard without risking a null pointer dereference<br />
if hci_register_dev() fails.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.293 (incluyendo) | 5.5 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10.237 (incluyendo) | 5.10.258 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15.181 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.135 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.88 (incluyendo) | 6.6.141 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.24 (incluyendo) | 6.12.91 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13.12 (incluyendo) | 6.14 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14.3 (incluyendo) | 6.18.33 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.10 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/194f029a4d7f739e44ebc1f473120187b4de5104
- https://git.kernel.org/stable/c/356dee1bcac4d0d9152390561fa63331ebff211b
- https://git.kernel.org/stable/c/3daa5818e473ed60eb69d8b5c71b651909d28c5a
- https://git.kernel.org/stable/c/68d39ea5e0adc9ecaea1ce8abd842ec972eb8718
- https://git.kernel.org/stable/c/a673cf6c4ac702cb79ac1f4d7fc4de763a6a3e40
- https://git.kernel.org/stable/c/ebb39b2d81731b83ee71a1ba6dd0291a57b5ac07
- https://git.kernel.org/stable/c/ed4033fb85ccaaf6c3983be3c7b037e48253d232
- https://git.kernel.org/stable/c/f4b69c35813c432973d340d3600c01de106ed474



