PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23462 Linux CVE debrief

CVE-2026-23462 is a Linux kernel Bluetooth HIDP use-after-free issue. The NVD record says the bug was fixed after a missing l2cap_conn reference drop when the user->remove callback is invoked, which can leave a stale connection object reachable during Bluetooth teardown. NVD rates the issue HIGH with CVSS 8.8 and lists broad kernel version coverage across multiple stable branches and early 7.0 release candidates.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Linux distribution security teams, kernel maintainers, and operators of systems that use Bluetooth HIDP or related Bluetooth connection teardown paths should prioritize this. Environments running affected kernel versions, especially where Bluetooth is enabled, should review patch status promptly.

Technical summary

The vulnerability is a kernel use-after-free in the Bluetooth HIDP path. According to the CVE description, the fix addresses failure to drop the l2cap_conn reference when user->remove is called. The provided trace shows l2cap_conn_free occurring during Bluetooth device shutdown/teardown, consistent with a lifetime management bug. NVD maps the weakness to CWE-416 and assigns CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

High. This is a kernel memory-safety flaw with high CVSS impact across confidentiality, integrity, and availability, and NVD indicates many affected kernel branches. Prioritize patching on systems with Bluetooth exposure.

Recommended defensive actions

  • Install the vendor or stable-kernel fix for CVE-2026-23462 on all affected systems.
  • Confirm your running kernel is outside the affected ranges listed by NVD, including the noted stable series and early 7.0 release candidates.
  • If immediate patching is not possible, reduce Bluetooth exposure on systems that do not require HIDP functionality.
  • Review fleet monitoring for crashes or warnings in Bluetooth teardown and connection-free paths.
  • Track downstream distro advisories for backported fixes matching the listed kernel branches.

Evidence notes

Source evidence comes from the NVD record and the CVE description. The record identifies CWE-416 and CVSS 8.8, describes the bug as a Linux kernel Bluetooth HIDP use-after-free caused by not dropping the l2cap_conn reference in the user->remove callback, and lists affected kernel version ranges plus patch references on git.kernel.org. The supplied trace shows l2cap_conn_free during Bluetooth device teardown, which supports the lifetime bug description.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23462 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23462

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23462 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23462

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/18b1263ece6431bd78fa6b61faaef5281203741c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/21a47a119f33df9bb157326846390d7e8e1b45ba

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/45ebe5b900200ac3e01f3470506a44a447825721

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4d37fa7582aa960ba23e10a7a2596a29f37ad281

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7c805b7d1e580eececcc92470292e3dbc42bc3f5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d955ccbf91ab74d76fe9e4eab2846a7d8a173075

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dbf666e4fc9bdd975a61bf682b3f75cb0145eedd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.