CVE-2026-68390

Source
https://cve.org/CVERecord?id=CVE-2026-68390
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68390.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68390
Downstream
Published
2026-08-10T12:04:09.373Z
Modified
2026-08-12T04:18:48.206565922Z
Summary
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hcisync: hold hdev->lock for hciconn_params lookups

hciconnparams_lookup requires hdev->lock be held, otherwise the list iteration or param access is not safe.

Hold hdev->lock for params lookups in hci_sync.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68390.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c530569adc19b5f0c62955de41f067bad34e3fe0
Fixed
8d892bec1dd134761cabec6ba23fe315d0f20f98
Fixed
c363202ec841df36421ec280eea3d5f94f556143

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68390.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68390.json"