{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "6083089ab00631617f9eac678df3ab050a9d837a"
            },
            {
              "fixed": "903227b6168bb99fd57d4e3c9c1b5014986198e0"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "a13f316e90fdb1fb6df6582e845aa9b3270f3581"
            },
            {
              "fixed": "83b22d7f7c384564fa42c3cf19bec715c693d7a2"
            },
            {
              "fixed": "70c397b62ee015e19b3924d9da741c8dda017819"
            },
            {
              "fixed": "61701912c58a05f6a043f097cc177a964abef348"
            },
            {
              "fixed": "b42cb640a0493d16b61ddd267420274be15efdc1"
            },
            {
              "fixed": "12917f591cea1af36087dba5b9ec888652f0b42a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "e4511a67fcdba9729d1c7cfc6d2e645c765ce801"
            },
            {
              "last_affected": "4ab81f16c68a602b2b69e333ae08d8748a9398de"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.1.83"
            },
            {
              "fixed": "6.1.118"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.4.16"
            },
            {
              "fixed": "6.5"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.5.3"
            },
            {
              "fixed": "6.6"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.118"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.145"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.6.0"
            },
            {
              "fixed": "6.12.97"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.18.39"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "7.1.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64405.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()\n\nhci_abort_conn() read hci_skb_event(hdev-\u003esent_cmd) when a connection\nwas pending, but hdev-\u003esent_cmd can be NULL while req_status is still\nHCI_REQ_PEND, leading to a NULL pointer dereference and a general\nprotection fault from the hci_rx_work() receive path.\n\nInstead of inspecting hdev-\u003esent_cmd, track the in-flight create\nconnection command with a new per-connection HCI_CONN_CREATE flag and\nroute all cancellation through hci_cancel_connect_sync(), which\ndispatches to a dedicated per-type cancel function. The create command\nis in exactly one of two states: still queued, or in flight. The cancel\nfunction holds cmd_sync_work_lock across the whole decision: the worker\ntakes this lock to dequeue every entry, so while it is held a queued\ncommand cannot start running and an in-flight command cannot complete\nand let the next command become pending. This keeps the flag test and\nhci_cmd_sync_cancel() atomic with respect to the worker, so a queued\ncommand is simply dequeued, and an in-flight command owned by this\nconnection is cancelled without the risk of cancelling an unrelated\ncommand that became pending in the meantime. CIS uses the same flag\nmechanism via HCI_CONN_CREATE_CIS but cannot be dequeued per-connection.\n\nhci_acl_create_conn_sync() and hci_le_create_conn_sync() clear\nHCI_CONN_CREATE after the create command completes, but the command\nstatus handler can free conn via hci_conn_del() (for example when the\ncontroller rejects the connection) while the worker is still blocked on\nthe connection complete event. Hold a reference on conn across the\ncreate command so the flag can be cleared without a use-after-free.",
  "id": "CVE-2026-64405",
  "modified": "2026-07-27T03:56:28.291882203Z",
  "published": "2026-07-25T08:50:47.262Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64405.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64405"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.8.0",
  "summary": "Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()"
}