{"id":"CVE-2024-26801","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPI…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPI…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 4.0, < 4.19.309","linux_kernel >= 4.20, < 5.4.271","linux_kernel >= 5.5, < 5.10.212","linux_kernel >= 5.11, < 5.15.151","linux_kernel >= 5.16, < 6.1.81","linux_kernel >= 6.2, < 6.6.21","linux_kernel >= 6.7, < 6.7.9","linux_kernel = 6.8"],"patched":["linux_kernel 6.7.9"],"published":"2024-04-04","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-26801","references":[{"url":"https://git.kernel.org/stable/c/2449007d3f73b2842c9734f45f0aadb522daf592","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ab9a19d896f5a0dd386e1f001c5309bc35f433b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45085686b9559bfbe3a4f41d3d695a520668f5e1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6dd0a9dfa99f8990a08eb8fdd8e79bee31c7d8e2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98fb98fd37e42fd4ce13ff657ea64503e24b6090","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da4569d450b193e39e87119fd316c0291b585d14","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd594cdc24f2e48dab441732e6dfcafd6b0711d1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0b278650f07acf2e0932149183458468a731c03","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2449007d3f73b2842c9734f45f0aadb522daf592","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/2ab9a19d896f5a0dd386e1f001c5309bc35f433b","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/45085686b9559bfbe3a4f41d3d695a520668f5e1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/6dd0a9dfa99f8990a08eb8fdd8e79bee31c7d8e2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/98fb98fd37e42fd4ce13ff657ea64503e24b6090","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/da4569d450b193e39e87119fd316c0291b585d14","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/dd594cdc24f2e48dab441732e6dfcafd6b0711d1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/e0b278650f07acf2e0932149183458468a731c03","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00422,"epssPercentile":0.36163,"ingestedAt":"2026-08-05T10:46:49.152Z","slug":"CVE-2024-26801","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPIO reset mechanism would\nfree the hci_dev and lead to a use-after-free in hci_error_reset.\n\nHere's the call trace observed on a ChromeOS device with Intel AX201:\n   queue_work_on+0x3e/0x6c\n   __hci_cmd_sync_sk+0x2ee/0x4c0 [bluetooth <HASH:3b4a6>]\n   ? init_wait_entry+0x31/0x31\n   __hci_cmd_sync+0x16/0x20 [bluetooth <HASH:3b4a 6>]\n   hci_error_reset+0x4f/0xa4 [bluetooth <HASH:3b4a 6>]\n   process_one_work+0x1d8/0x33f\n   worker_thread+0x21b/0x373\n   kthread+0x13a/0x152\n   ? pr_cont_work+0x54/0x54\n   ? kthread_blkcg+0x31/0x31\n    ret_from_fork+0x1f/0x30\n\nThis patch holds the reference count on the hci_dev while processing\na HCI_EV_HARDWARE_ERROR event to avoid potential crash.\n\n## Affected\n\n- `linux_kernel >= 4.0, < 4.19.309`\n- `linux_kernel >= 4.20, < 5.4.271`\n- `linux_kernel >= 5.5, < 5.10.212`\n- `linux_kernel >= 5.11, < 5.15.151`\n- `linux_kernel >= 5.16, < 6.1.81`\n- `linux_kernel >= 6.2, < 6.6.21`\n- `linux_kernel >= 6.7, < 6.7.9`\n- `linux_kernel = 6.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7.9`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}