CVE-2026-97908
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev<br />
<br />
The command and ACL RPMsg endpoints store struct btqcomsmd as their<br />
callback private data. The receive callbacks dereference btq->hdev<br />
without taking an hci_dev reference.<br />
<br />
The current teardown order frees the hci_dev before destroying the RPMsg<br />
endpoints in both the hci_register_dev() error path and the driver remove<br />
path. If WCNSS delivers data in that window, the endpoint callback can<br />
run with an already freed hci_dev and pass it to the Bluetooth core.<br />
<br />
For qcom_smd endpoints, rpmsg_destroy_ept() closes the channel and clears<br />
the callback under the channel recv_lock. The receive path holds the same<br />
lock while invoking the callback, so destroying the endpoints first both<br />
prevents new callbacks and serializes with any callback already running.<br />
<br />
Destroy the command and ACL endpoints before hci_free_dev(). Keep<br />
hci_unregister_dev() first during remove so the HCI core stops issuing<br />
operations before the transport endpoints are shut down. In the full<br />
registration-error cleanup path, return directly after freeing the hci_dev<br />
to avoid falling through to the partial-construction labels and destroying<br />
the endpoints twice.


