CVE-2026-97977

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix UAF of btusb_data by rx_work btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns. btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data: while ((skb = skb_dequeue(&data->acl_q))) data->recv_acl(data->hdev, skb); Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 5.17 and later are affected. Fixed in 6.1.189, 6.6.158, 6.12.111, 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 5.17
Fixed in
✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97977?

    CVE-2026-97977 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.17 onward and has been patched in 6.1.189, 6.6.158, 6.12.111 and others. CVE-2026-97977 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97977?

    Yes. CVE-2026-97977 has been patched. Fixed versions include 6.1.189, 6.6.158, 6.12.111 and others. If you are running Linux kernel 5.17 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97977 actively exploited?

    No. CVE-2026-97977 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.