CVE-2026-98294

Source
https://cve.org/CVERecord?id=CVE-2026-98294
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98294.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98294
Downstream
Published
2026-10-06T08:45:53Z
Modified
2026-10-08T02:52:56Z
Summary
Bluetooth: hci_qca: Do not write to the serial port after it is closed
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_qca: Do not write to the serial port after it is closed

hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP is set (for example, for the WCN399x family). A failed hci_dev_open_sync() following a successful qca_setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs_on is left true. qca_serdev_remove() then passes its power->vregs_on test and calls qca_power_off(), which writes to the closed port unconditionally.

Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca_power_off() was still named qca_power_shutdown():

Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: tty_set_termios+0x50/0x238 (P) ttyport_set_baudrate+0x84/0xc0 serdev_device_set_baudrate+0x24/0x40 qca_power_shutdown+0x158/0x1fc [hci_uart] qca_serdev_remove+0x54/0x68 [hci_uart] serdev_drv_remove+0x1c/0x2c device_remove+0x4c/0x80 device_release_driver_internal+0x1cc/0x224 device_driver_detach+0x18/0x24 unbind_store+0xb4/0xc0

Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down.

The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98294.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3
Fixed
a5414b0a9464b863733c8bd97493cb443a210ec4
Fixed
15754e4ec47ac5d117c9609c34a49ed6980ac4a1
Fixed
4e93c65f87825e1e012bce56615320aeb123815d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98294.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98294.json"