CVE-2026-97975

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() A NULL pointer dereference in klist_put() occurs when a child device (such as a BNEP network device in bnep_session) is concurrently being unregistered while hci_conn_del_sysfs() reparents child devices. This is caused by a race condition between hci_conn_del_sysfs() and concurrent child device unregistration (e.g. bnep_session calling unregister_netdev()). During device unregistration, device_del() snapshots a non-NULL parent pointer. Concurrently, hci_conn_del_sysfs() finds the child device using device_find_any_child() and calls device_move() to reparent it to NULL, which removes the node from its parent's klist and clears knode_parent. Subsequently, device_del() calls klist_del(&dev->p->knode_parent) using the stale parent snapshot, causing klist_put() to dereference knode_klist(n)->put on an already removed node, resulting in a NULL pointer dereference. This race was introduced by commit 27aabf27fd01 ("Bluetooth: fix use-after-free in device_for_each_child()"), which replaced device_find_child(..., __match_tty) with device_find_any_child() in hci_conn_del_sysfs(). That change was intended to avoid a use-after-free where conn->dev outlived its parent hdev->dev when child devices held references to conn->dev, because conn->dev only held a reference to hdev->dev while registered in sysfs. Fix the issue properly by taking an explicit reference to the parent device with get_device(&hdev->dev) in hci_conn_init_sysfs() and dropping it with put_device(parent) in bt_link_release() when the conn device is freed. This ensures that hdev->dev remains valid for the entire lifecycle of conn->dev, resolving the underlying use-after-free. With the parent reference held properly, restore the __match_tty filter in hci_conn_del_sysfs() so that device_move() is only invoked on persistent RFCOMM TTY devices as originally intended, eliminating the race condition with unregistering network devices.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-25
Patch available
Yes

Affected versions

Linux kernel versions 5.4.297, 5.10.231, 5.15.174, 6.1.120, 6.6.64, 6.11.11, 6.12.2, 6.13 and later are affected. Fixed in 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 5.4.297 ≥ 5.10.231 ≥ 5.15.174 ≥ 6.1.120 ≥ 6.6.64 ≥ 6.11.11 ≥ 6.12.2 ≥ 6.13
Fixed in
✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97975?

    CVE-2026-97975 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.4.297 onward and has been patched in 6.18.53, 7.2.7 and 7.3-rc3. CVE-2026-97975 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97975?

    Yes. CVE-2026-97975 has been patched. Fixed versions include 6.18.53, 7.2.7 and 7.3-rc3. If you are running Linux kernel 5.4.297 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97975 actively exploited?

    No. CVE-2026-97975 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.