CVE-2026-55330Critical· 9.8▾ MidnightIn BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 9.8
none → critical
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56952Medium· 6.7In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check
CVE-2026-56906High· 7.0In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition
CVE-2026-56936Medium· 6.8In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-55307Medium· 4.4In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code
CVE-2026-58751Medium· 6.7In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2025-20780High· 7.8In display, there is a possible memory corruption due to use after free