CVE-2026-64470

Source
https://cve.org/CVERecord?id=CVE-2026-64470
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64470.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64470
Downstream
Related
Published
2026-07-25T08:51:34.673Z
Modified
2026-08-18T03:30:50.378622095Z
Summary
Bluetooth: btusb: fix use-after-free on marvell probe failure
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: fix use-after-free on marvell probe failure

Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback.

This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64470.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a4ccc9e33d2f01532bcceb621ea06bbf4db6efac
Fixed
1edd524de5cc8143ece9c42c466346983dc5b5ed
Fixed
0ccb1cb0a464dab78284c34196cd3e8e18bab4c4
Fixed
631de465aba7f8ae46478bf5f598111412e8eff8
Fixed
6e1b10df890f4663cb38af9fc1c93d36747b75af
Fixed
92c736866244340497a8a65afe2ac25354c2bf5e
Fixed
a7e941a395711791c7e98d9870c6562c2c9e9ef2
Fixed
838c917a2f16eefe68def800ebf48a2af591149a
Fixed
c5b600a3c05b1a7a110d558df935a8fc8a471c79

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64470.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64470.json"