Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97908

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev<br /> <br /> The command and ACL RPMsg endpoints store struct btqcomsmd as their<br /> callback private data. The receive callbacks dereference btq-&gt;hdev<br /> without taking an hci_dev reference.<br /> <br /> The current teardown order frees the hci_dev before destroying the RPMsg<br /> endpoints in both the hci_register_dev() error path and the driver remove<br /> path. If WCNSS delivers data in that window, the endpoint callback can<br /> run with an already freed hci_dev and pass it to the Bluetooth core.<br /> <br /> For qcom_smd endpoints, rpmsg_destroy_ept() closes the channel and clears<br /> the callback under the channel recv_lock. The receive path holds the same<br /> lock while invoking the callback, so destroying the endpoints first both<br /> prevents new callbacks and serializes with any callback already running.<br /> <br /> Destroy the command and ACL endpoints before hci_free_dev(). Keep<br /> hci_unregister_dev() first during remove so the HCI core stops issuing<br /> operations before the transport endpoints are shut down. In the full<br /> registration-error cleanup path, return directly after freeing the hci_dev<br /> to avoid falling through to the partial-construction labels and destroying<br /> the endpoints twice.

Impacto