{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: mgmt: fix 'hdev-\u003ediscovery.uuids' NULL dereference  'uuid_count' member of struct 'discovery_state' is assigned and read without any locks, so there is a chance of situation when uuid_count != 0, but uuids is NULL and there will be NULL pointer dereference.  Possible race: 'hci_update_passive_scan_sync'   'hci_discovery_filter_clear'     hdev-\u003ediscovery.uuid_count = 0;       \u003c----------------------preempted-----------------------------\u003e                         'start_service_discovery'                           // Set uuid_count to value != 0                           hdev-\u003ediscovery.uuid_count = uuid_count;                           hdev-\u003ediscovery.uuids = kmemdup(...);       \u003c----------------------preempted-----------------------------\u003e     spin_lock(\u0026hdev-\u003ediscovery.lock);     kfree(hdev-\u003ediscovery.uuids);     hdev-\u003ediscovery.uuids = NULL;     spin_unlock(\u0026hdev-\u003ediscovery.lock);  Now uuids == NULL and uuid_count != 0. So 'mgmt_device_found' -\u003e 'is_filter_match' -\u003e 'eir_has_uuids' receives non consistent discovery state, where NULL dereference of uuids happens.  To fix it let's add discovery.lock around every read/write of uuid_count, uuids pair of struct members. It is also important to assign uuid_count value only after success kmemdup() allocation in start_service_discovery(), otherwise uuids is NULL, because kmemdup failed, but uuid_count is already assigned to non zero value.  The following panic happens:  [ ] ------------[ cut here ]------------ [ ] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ ] Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP [ ] CPU: 0 PID: 15056 Comm: kworker/u9:2 [ ] Workqueue: hci0 hci_rx_work [ ] pstate: 10400009 (nzcV daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ ] pc : eir_has_uuids+0x2d8/0x590 [ ] lr : is_filter_match+0x258/0x320 ... [ ] Call trace: [ ]  eir_has_uuids+0x2d8/0x590 [ ]  is_filter_match+0x258/0x320 [ ]  mgmt_device_found+0x5b0/0xafc [ ]  process_adv_report.part.0+0x8c8/0xf14 [ ]  hci_le_adv_report_evt+0x338/0x3f0 [ ]  hci_le_meta_evt+0x1f0/0x4c8 [ ]  hci_event_packet+0x440/0xc9c [ ]  hci_rx_work+0x44c/0xaf8 [ ]  process_one_work+0x54c/0x103c [ ]  worker_thread+0x6c4/0x10c4 [ ]  kthread+0x274/0x2ec [ ]  ret_from_fork+0x10/0x20 [ ] Code: 14000004 91004021 eb14003f 54000180 (f9400024) [ ] ---[ end trace 0000000000000000 ]---",
  "id": "DEBIAN-CVE-2026-93247",
  "modified": "2026-09-29T10:47:35.770793425Z",
  "published": "2026-09-24T16:17:20.803Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-93247"
    }
  ],
  "upstream": [
    "CVE-2026-93247"
  ]
}