PatchSiren cyber security CVE debrief
CVE-2026-23462 Linux CVE debrief
CVE-2026-23462 is a Linux kernel Bluetooth HIDP use-after-free issue. The NVD record says the bug was fixed after a missing l2cap_conn reference drop when the user->remove callback is invoked, which can leave a stale connection object reachable during Bluetooth teardown. NVD rates the issue HIGH with CVSS 8.8 and lists broad kernel version coverage across multiple stable branches and early 7.0 release candidates.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Linux distribution security teams, kernel maintainers, and operators of systems that use Bluetooth HIDP or related Bluetooth connection teardown paths should prioritize this. Environments running affected kernel versions, especially where Bluetooth is enabled, should review patch status promptly.
Technical summary
The vulnerability is a kernel use-after-free in the Bluetooth HIDP path. According to the CVE description, the fix addresses failure to drop the l2cap_conn reference when user->remove is called. The provided trace shows l2cap_conn_free occurring during Bluetooth device shutdown/teardown, consistent with a lifetime management bug. NVD maps the weakness to CWE-416 and assigns CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
High. This is a kernel memory-safety flaw with high CVSS impact across confidentiality, integrity, and availability, and NVD indicates many affected kernel branches. Prioritize patching on systems with Bluetooth exposure.
Recommended defensive actions
- Install the vendor or stable-kernel fix for CVE-2026-23462 on all affected systems.
- Confirm your running kernel is outside the affected ranges listed by NVD, including the noted stable series and early 7.0 release candidates.
- If immediate patching is not possible, reduce Bluetooth exposure on systems that do not require HIDP functionality.
- Review fleet monitoring for crashes or warnings in Bluetooth teardown and connection-free paths.
- Track downstream distro advisories for backported fixes matching the listed kernel branches.
Evidence notes
Source evidence comes from the NVD record and the CVE description. The record identifies CWE-416 and CVSS 8.8, describes the bug as a Linux kernel Bluetooth HIDP use-after-free caused by not dropping the l2cap_conn reference in the user->remove callback, and lists affected kernel version ranges plus patch references on git.kernel.org. The supplied trace shows l2cap_conn_free during Bluetooth device teardown, which supports the lifetime bug description.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23462 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23462
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23462 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23462
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/18b1263ece6431bd78fa6b61faaef5281203741c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/21a47a119f33df9bb157326846390d7e8e1b45ba
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/45ebe5b900200ac3e01f3470506a44a447825721
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4d37fa7582aa960ba23e10a7a2596a29f37ad281
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7c805b7d1e580eececcc92470292e3dbc42bc3f5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d955ccbf91ab74d76fe9e4eab2846a7d8a173075
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dbf666e4fc9bdd975a61bf682b3f75cb0145eedd
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.