In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisync: fix UAF in hcilecreatecis_sync
hcilecreatecissync() dereferences conn->conntimeout after releasing both rcureadlock() and hcidevlock(hdev). The conn pointer was obtained from an RCU-protected iteration over hdev->connhash.list and is not valid once these locks are dropped. A concurrent disconnect can free the hci_conn between the unlock and the dereference, causing a use-after-free read.
The cancellation mechanism in hciconndel() cannot prevent this because hcilecreatecispending() queues hcicreatecis_sync with data=NULL:
hci_cmd_sync_queue(hdev, hci_create_cis_sync, NULL, NULL);
While hciconndel() dequeues with data=conn:
hci_cmd_sync_dequeue(hdev, NULL, conn, NULL);
Since NULL != conn, the lookup in hcicmdsynclookup_entry() never matches, and the pending work item is not cancelled.
Fix this by saving conn->conn_timeout into a local variable while the locks are still held, so the stale conn pointer is never dereferenced after unlock.
This is the same class of bug as the one fixed by commit 035c25007c9e ("Bluetooth: hcisync: Fix UAF on lereadfeaturescomplete") which addressed the identical pattern in a different function.
This vulnerability was identified using 0sec.ai, an open-source automated security auditing platform (https://github.com/0sec-labs).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63944.json",
"cna_assigner": "Linux"
}