---
id: CVE-2026-98295
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: coredump: Quiesce dump work on unregister

  hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
  queue dump_rx without holding an hdev referen…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: coredump: Quiesce dump work on unregister

  hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
  queue dump_rx without holding an hdev referen…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda <
    24af375d7d8aa5f698e4dc41317102f44114351a
  - >-
    Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda <
    dcaf10ef27f928568c25de3e9fc242e538de5c67
  - >-
    Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda <
    82699d1b727ba5980b94f1eb8dc3d346f41b7c67
  - >-
    Linux >= 9695ef876fd122cb7bbc04a4a93b8727d2e36bda <
    d236517c264e41dc09833c708ef23bccb7a91219
  - Linux deb8156ebe5cb63a5988e7f86cc46aa062527c2b
  - Linux >= 6.1.188 < 6.2
  - Linux 6.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:20.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98295'
references:
  - url: 'https://git.kernel.org/stable/c/24af375d7d8aa5f698e4dc41317102f44114351a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/82699d1b727ba5980b94f1eb8dc3d346f41b7c67'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d236517c264e41dc09833c708ef23bccb7a91219'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dcaf10ef27f928568c25de3e9fc242e538de5c67'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.418Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: coredump: Quiesce dump work on unregister

hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
