AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68389

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth subsystem, specifically in the handling of memory dumps during the qca_controller_memdump process. An attacker could exploit this flaw to operate on freed memory, potentially leading to system instability or denial of service due to blocked operations. Organizations using Linux systems with Bluetooth capabilities should prioritize addressing this issue to mitigate risks associated with memory management errors.

CVE
CVE-2026-68389
Severity
HIGH
CVSS
8.8
EPSS
0.26%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_memdump() allocates qca->qca_memdump before processing the first dump packet. For a sequence-zero packet it then disables IBS, marks memdump collection active, and reads the advertised dump size. If the controller reports a zero dump size, the error path frees the local qca_memdump object and returns without clearing qca->qca_memdump or undoing the collection state. A later memdump work item initializes its local pointer from qca->qca_memdump and skips allocation when that pointer is non-NULL, so it can operate on freed memory. The stale collection and IBS-disabled flags can also leave waiters or later transmit handling blocked behind an aborted dump. Clear the saved pointer and memdump state before returning from the invalid-size path, matching the cleanup used when hci_devcd_init() fails. A static analysis checker reported the stale memdump state, and manual source review confirmed the invalid-size failure path.