CVE-2026-97977

Source
https://cve.org/CVERecord?id=CVE-2026-97977
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97977.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97977
Downstream
Published
2026-09-25T10:23:15Z
Modified
2026-09-26T03:48:27Z
Summary
Bluetooth: btusb: Fix UAF of btusb_data by rx_work
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: Fix UAF of btusb_data by rx_work

btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.

btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data:

while ((skb = skb_dequeue(&data->acl_q)))
	data->recv_acl(data->hdev, skb);

Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97977.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
800fe5ec302e1ebbf5e3f891f886deecd49c7132
Fixed
472d005622525b7be155cac99dde2252b0163bd1
Fixed
93b59937bda3fffc6386c79f5544a39bc680c8e8
Fixed
fa391adb9c755515a89993634745e9079e5ef37c
Fixed
1c12c3117639e78940959d956519c758c57d0849

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97977.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97977.json"