---
id: CVE-2026-98294
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_qca: Do not write to the serial port after it is closed

  hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP
  is set (for example, f…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_qca: Do not write to the serial port after it is closed

  hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP
  is set (for example, f…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3 <
    a5414b0a9464b863733c8bd97493cb443a210ec4
  - >-
    Linux >= fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3 <
    15754e4ec47ac5d117c9609c34a49ed6980ac4a1
  - >-
    Linux >= fa9ad876b8e0ebd2b4367ef1580f89be64ebd5d3 <
    4e93c65f87825e1e012bce56615320aeb123815d
  - Linux 4.19
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:19.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98294'
references:
  - url: 'https://git.kernel.org/stable/c/15754e4ec47ac5d117c9609c34a49ed6980ac4a1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e93c65f87825e1e012bce56615320aeb123815d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a5414b0a9464b863733c8bd97493cb443a210ec4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.417Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_qca: Do not write to the serial port after it is closed

hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP
is set (for example, for the WCN399x family). A failed hci_dev_open_sync()
following a successful qca_setup() calls hdev->close() but not
hdev->shutdown(), so the port is closed while power->vregs_on is left true.
qca_serdev_remove() then passes its power->vregs_on test and calls
qca_power_off(), which writes to the closed port unconditionally.

Seen on a WCN3988 by unbinding the driver after a controller failure. The
trace below is from a 7.0.0 based kernel, where qca_power_off() was still
named qca_power_shutdown():

  Unable to handle kernel NULL pointer dereference at virtual address
  0000000000000038
  Call trace:
   tty_set_termios+0x50/0x238 (P)
   ttyport_set_baudrate+0x84/0xc0
   serdev_device_set_baudrate+0x24/0x40
   qca_power_shutdown+0x158/0x1fc [hci_uart]
   qca_serdev_remove+0x54/0x68 [hci_uart]
   serdev_drv_remove+0x1c/0x2c
   device_remove+0x4c/0x80
   device_release_driver_internal+0x1cc/0x224
   device_driver_detach+0x18/0x24
   unbind_store+0xb4/0xc0

Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place
it closes the port, before writing to it. The regulator disable is left
unconditional so the controller is still powered down.

The dangling serport->tty that turns this into a use-after-free is
addressed in a separate patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
