{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.107-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.107-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: fix LE list UAF on reset  hci_cc_reset() clears the LE accept and resolving lists without taking hdev-\u003elock. Other command-complete handlers serialize updates to these lists with that lock, and the debugfs readers hold it while walking them.  This permits the reset completion and a debugfs read to interleave as follows:    hci_rx_work                 debugfs reader   -----------                 --------------                               lock hdev-\u003elock                               fetch current entry   list_del(entry)   kfree(entry)                               read entry fields  The reader then dereferences a freed list entry and may follow its stale next pointer.  KASAN reported:    BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180   Read of size 1 at addr ffff8881015dab16 by task poc/95    Call Trace:    white_list_show+0x15f/0x180    seq_read_iter+0x3ff/0x1190    seq_read+0x267/0x3d0    vfs_read+0x177/0xa20    ksys_read+0xf7/0x1c0    Allocated by task 91:    hci_bdaddr_list_add+0x1a6/0x3a0    hci_cc_le_add_to_accept_list+0xab/0x140    hci_cmd_complete_evt+0x26c/0x9a0    hci_event_packet+0x454/0xb20    hci_rx_work+0x293/0x730    Freed by task 90:    kfree+0x131/0x3c0    hci_bdaddr_list_clear+0xd8/0x160    hci_cc_reset+0x28a/0x370    hci_cmd_complete_evt+0x26c/0x9a0    hci_event_packet+0x454/0xb20    hci_rx_work+0x293/0x730  Take hdev-\u003elock around both list clears. This matches the existing mutation and traversal locking convention.",
  "id": "DEBIAN-CVE-2026-80764",
  "modified": "2026-09-19T21:47:26.009732426Z",
  "published": "2026-09-04T16:18:01.617Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80764"
    }
  ],
  "upstream": [
    "CVE-2026-80764"
  ]
}