CVE-2026-98295

Source
https://cve.org/CVERecord?id=CVE-2026-98295
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98295.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98295
Downstream
Published
2026-10-06T08:45:54Z
Modified
2026-10-08T02:52:56Z
Summary
Bluetooth: coredump: Quiesce dump work on unregister
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers queue dump_rx without holding an hdev reference. Unregister leaves both works live, so disconnecting during an active dump lets them access hdev after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate under dump_q.lock before disabling both works, then free the active buffer and queued packets under hci_dev_lock. Serializing the gate with enqueue prevents controller-specific workers from adding packets after the final purge.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98295.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9695ef876fd122cb7bbc04a4a93b8727d2e36bda
Fixed
24af375d7d8aa5f698e4dc41317102f44114351a
Fixed
dcaf10ef27f928568c25de3e9fc242e538de5c67
Fixed
82699d1b727ba5980b94f1eb8dc3d346f41b7c67
Fixed
d236517c264e41dc09833c708ef23bccb7a91219
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.1.188
Fixed
6.2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
deb8156ebe5cb63a5988e7f86cc46aa062527c2b

Affected versions

v6.*
v6.1.188
v6.1.189

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98295.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98295.json"