In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisync: Set HCICMDDRAINWORKQUEUE during device close
Since hcidevclosesync() can now be called during the reset path, we should also set HCICMDDRAINWORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63974.json",
"cna_assigner": "Linux"
}