CVE-2026-23462
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23462 is a use-after-free (UAF) vulnerability in the Linux kernel's Bluetooth HIDP (Human Interface Device Profile) subsystem. The flaw arises because the l2cap_conn reference is not properly dropped when the user->remove callback is invoked, leading to potential memory corruption. It was published on April 3, 2026, and affects multiple Linux kernel version ranges from 3.10 through 7.0-rc4. It carries a CVSS v3.1 base score of 8.8 (High), exploitable from an adjacent network without credentials (GitHub Advisory).

Technical details

The root cause is classified as CWE-416 (Use After Free): when the HIDP subsystem's user->remove callback is triggered during a Bluetooth device disconnection or HCI device close, the l2cap_conn reference count is not decremented, leaving a dangling reference. A subsequent deallocation of the l2cap_conn object (e.g., via l2cap_conn_dell2cap_conn_free) can then be triggered by an adjacent attacker manipulating Bluetooth connection teardown, causing the kernel to operate on freed memory. The call trace from the bug report shows the path: hci_dev_close_synchci_conn_hash_flushl2cap_disconn_cfml2cap_conn_dell2cap_conn_free. No authentication or user interaction is required; the attacker only needs to be within Bluetooth range (GitHub Advisory).

Impact

Successful exploitation can allow an adjacent, unauthenticated attacker to execute arbitrary code with kernel privileges, read sensitive kernel memory, or crash the system (denial of service). The high confidentiality, integrity, and availability impact scores reflect the potential for full kernel compromise, which could enable privilege escalation, lateral movement within a network, and exposure of sensitive data processed by the kernel (GitHub Advisory).

Mitigation and workarounds

Patches have been released across multiple stable Linux kernel branches. Administrators should upgrade to the following fixed versions or later: 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, or 6.19.10. Patches are available via the stable kernel tree at git.kernel.org. As an interim workaround if patching is not immediately possible, disable Bluetooth functionality on affected systems or restrict Bluetooth connectivity to trusted, paired devices only. Distribution-specific updates have been issued by SUSE (SUSE-SU-2026:2068-1, SUSE-SU-2026:2111-1, SUSE-SU-2026:2195-1, SUSE-SU-2026:2215-1, SUSE-SU-2026:2238-1) and Debian (GitHub Advisory).

Community reactions

The vulnerability was announced via the Linux kernel CVE mailing list (lore.kernel.org) on April 3, 2026, and subsequently tracked by major vulnerability databases including NVD and VulnDB. SUSE issued multiple security advisories addressing this CVE across their product lines, and Debian accepted updated kernel packages. The Yocto Project security mailing list also circulated notices regarding the fix. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vendor patch tracking (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management