CVE-2026-68085
HighIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is pending and blocks queueing it again. Currently this bit is not cleared when canceling the work in hci_uart_close(), which blocks future writes when device is reopened later if write_work was pending. Fix by clearing HCI_UART_SENDING when canceling the work. Also make clearing of tx_skb safe by using disable_work_sync + enable_work instead of just cancel_work_sync. hci_uart_flush() purges the proto tx queue so we can cancel the pending write_work there, instead of doing it just in hci_uart_close(). Re-enable and possibly requeue the work after queue flush.
CVSS 3.1 score
8.0
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected versions
Linux kernel versions
6.12.92,
6.18.34,
5.10.258,
5.15.209,
6.1.175,
6.6.142,
7.0.11,
7.1
and later are affected. Fixed in
6.12.96,
6.18.39,
7.1.4,
7.2
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-68085?
CVE-2026-68085 is a High severity Linux kernel vulnerability with a CVSS score of 8.0 out of 10 . It affects Linux kernel versions from 6.12.92 onward and has been patched in 6.12.96, 6.18.39, 7.1.4 and others. CVE-2026-68085 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2026-68085?
CVE-2026-68085 has a CVSS score of 8.0 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2026-68085?
Yes. CVE-2026-68085 has been patched. Fixed versions include 6.12.96, 6.18.39, 7.1.4 and others. If you are running Linux kernel 6.12.92 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-68085 actively exploited?
No. CVE-2026-68085 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.