In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcicore: Fix UAF in hciunregister_dev()
hciunregisterdev() does not disable cmdtimer and ncmdtimer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free.
Add disabledelayedworksync() calls alongside the existing disablework_sync() calls to ensure both timers are fully quiesced before teardown proceeds.