{"id":"CVE-2026-64471","summary":"Bluetooth: btusb: fix use-after-free on registration failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on registration failure\n\nMake sure to release the sibling interfaces in case controller\nregistration fails to avoid use-after-free and double-free when they are\neventually disconnected.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths.","modified":"2026-07-27T04:03:22.755128264Z","published":"2026-07-25T08:51:35.245Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64471.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/14e02f1449ba425a44dedbec9a21efafb056e09f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ce5012944afaddbda939ec6bae9800fce84abbc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/468fcdfaeb937163dd250773a9fed17ab1fa203c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8db0ce3de78367f61c2970c0f16d9adee8830a23"},{"type":"WEB","url":"https://git.kernel.org/stable/c/da7d7758fe884b256ddc9fef562e5ddef7952383"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e09ac7d0c6859a360bf36e7104aef03f88184e0b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6313b800da61a26c2fdd5eba0105e197c0ab3bc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eedc6867ebad73edbfaf9a0a65fbef7115cc4753"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64471.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64471"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"9bfa35fe422c74882e27cc54450a5f76c96aad68"},{"fixed":"e09ac7d0c6859a360bf36e7104aef03f88184e0b"},{"fixed":"468fcdfaeb937163dd250773a9fed17ab1fa203c"},{"fixed":"1ce5012944afaddbda939ec6bae9800fce84abbc"},{"fixed":"e6313b800da61a26c2fdd5eba0105e197c0ab3bc"},{"fixed":"14e02f1449ba425a44dedbec9a21efafb056e09f"},{"fixed":"8db0ce3de78367f61c2970c0f16d9adee8830a23"},{"fixed":"da7d7758fe884b256ddc9fef562e5ddef7952383"},{"fixed":"eedc6867ebad73edbfaf9a0a65fbef7115cc4753"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64471.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.27"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64471.json"}}],"schema_version":"1.7.5"}