CVE-2026-23462HIGH 8.8EPSS p18.0%

CVE-2026-23462CVE-2026-23462

linux / linux_kernel

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping l2cap_conn reference when user->remove callback is called: [ 97.809249] l2cap_conn_free: freeing conn ffff88810a171c00 [ 97.809907] CPU: 1 UID: 0 PID: 1419 Comm: repro_standalon Not tainted 7.0.0-rc1-dirty #14 PREEMPT(lazy) [ 97.809935] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 [ 97.809947] Call Trace: [ 97.809954] <TASK> [ 97.809961] dump_stack_lvl (lib/dump_stack.c:122) [ 97.809990] l2cap_conn_free (net/bluetooth/l2cap_core.c:1808) [ 97.810017] l2cap_conn_del (./include/linux/kref.h:66 net/bluetooth/l2cap_core.c:1821 net/bluetooth/l2cap_core.c:1798) [ 97.810055] l2cap_disconn_cfm (net/bluetooth/l2cap_core.c:7347 (discriminator 1) net/bluetooth/l2cap_core.c:7340 (discriminator 1)) [ 97.810086] ? __pfx_l2cap_disconn_cfm (net/bluetooth/l2cap_core.c:7341)

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.26% probability of exploitation · percentile 18.0% · 2026-08-03T12:00:16Z
Published2026-04-03
Last modified2026-07-24

Underlying weaknesses· 1

CWE-416

References

  1. https://git.kernel.org/stable/c/18b1263ece6431bd78fa6b61faaef5281203741c
  2. https://git.kernel.org/stable/c/21a47a119f33df9bb157326846390d7e8e1b45ba
  3. https://git.kernel.org/stable/c/45ebe5b900200ac3e01f3470506a44a447825721
  4. https://git.kernel.org/stable/c/4d37fa7582aa960ba23e10a7a2596a29f37ad281
  5. https://git.kernel.org/stable/c/7c805b7d1e580eececcc92470292e3dbc42bc3f5
  6. https://git.kernel.org/stable/c/d955ccbf91ab74d76fe9e4eab2846a7d8a173075
  7. https://git.kernel.org/stable/c/dbf666e4fc9bdd975a61bf682b3f75cb0145eedd
  8. https://git.kernel.org/stable/c/f8b6ed2f06d3baa44f347a0fa2af52433f386463

1

TypeTargetConfidenceTier
WeaknessUse After Freecwe-4160%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-43322
CVE
CVE-2026-23461
CVE
CVE-2024-26886
CVE
CVE-2026-31393
CVE
CVE-2026-23395
CVE
CVE-2026-43018
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.