SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80692

HIGH · CVSS 8.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's Bluetooth subsystem could lead to a theoretical use-after-free (UAF) condition if a connection is freed while the hci_sync task is executing. This could potentially allow an attacker to exploit the flaw, impacting systems that rely on Bluetooth functionality. Organizations using affected Linux distributions should prioritize patching to mitigate any risks associated with this vulnerability.

CVE
CVE-2026-80692
Severity
HIGH
CVSS
8.8
EPSS
0.22%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.