{"id":"CVE-2026-98295","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: coredump: Quiesce dump work on unregister\n\nhci_devcd_handle_pkt_init() arms dump_timeout and coredump producers\nqueue dump_rx without holding an hdev referen…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: coredump: Quiesce dump work on unregister\n\nhci_devcd_handle_pkt_init() arms dump_timeout and coredump producers\nqueue dump_rx without holding an hdev referen…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda < 24af375d7d8aa5f698e4dc41317102f44114351a","Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda < dcaf10ef27f928568c25de3e9fc242e538de5c67","Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda < 82699d1b727ba5980b94f1eb8dc3d346f41b7c67","Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda < d236517c264e41dc09833c708ef23bccb7a91219","Linux deb8156ebe5cb63a5988e7f86cc46aa062527c2b","Linux >= 6.1.188 < 6.2","Linux 6.4"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:20.133","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98295","references":[{"url":"https://git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.418Z","slug":"CVE-2026-98295","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: coredump: Quiesce dump work on unregister\n\nhci_devcd_handle_pkt_init() arms dump_timeout and coredump producers\nqueue dump_rx without holding an hdev reference. Unregister leaves both\nworks live, so disconnecting during an active dump lets them access hdev\nafter hci_release_dev() frees it.\n\nShut down coredump processing during unregister. Close the producer gate\nunder dump_q.lock before disabling both works, then free the active buffer\nand queued packets under hci_dev_lock. Serializing the gate with enqueue\nprevents controller-specific workers from adding packets after the final\npurge.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}