CVE-2026-98294

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Do not write to the serial port after it is closed hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP is set (for example, for the WCN399x family). A failed hci_dev_open_sync() following a successful qca_setup() calls hdev->close() but not hdev->shutdown(), so the port is closed while power->vregs_on is left true. qca_serdev_remove() then passes its power->vregs_on test and calls qca_power_off(), which writes to the closed port unconditionally. Seen on a WCN3988 by unbinding the driver after a controller failure. The trace below is from a 7.0.0 based kernel, where qca_power_off() was still named qca_power_shutdown(): Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: tty_set_termios+0x50/0x238 (P) ttyport_set_baudrate+0x84/0xc0 serdev_device_set_baudrate+0x24/0x40 qca_power_shutdown+0x158/0x1fc [hci_uart] qca_serdev_remove+0x54/0x68 [hci_uart] serdev_drv_remove+0x1c/0x2c device_remove+0x4c/0x80 device_release_driver_internal+0x1cc/0x224 device_driver_detach+0x18/0x24 unbind_store+0xb4/0xc0 Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place it closes the port, before writing to it. The regulator disable is left unconditional so the controller is still powered down. The dangling serport->tty that turns this into a use-after-free is addressed in a separate patch.

Package Linux Kernel
Published 2026-10-06
Last modified 2026-10-06
Patch available
Yes

Affected versions

Linux kernel versions 4.19 and later are affected. Fixed in 6.18.54, 7.2.8, 7.3-rc4 and their respective stable series.

Affected from
≥ 4.19
Fixed in
✓ 6.18.54 6.18.x ✓ 7.2.8 7.2.x ✓ 7.3-rc4

Frequently asked questions

  • What is CVE-2026-98294?

    CVE-2026-98294 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.19 onward and has been patched in 6.18.54, 7.2.8 and 7.3-rc4. CVE-2026-98294 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98294?

    Yes. CVE-2026-98294 has been patched. Fixed versions include 6.18.54, 7.2.8 and 7.3-rc4. If you are running Linux kernel 4.19 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98294 actively exploited?

    No. CVE-2026-98294 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.