PatchSiren cyber security CVE debrief
CVE-2026-45835 Linux CVE debrief
A null-pointer dereference vulnerability exists in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) subsystem. The flaw occurs in `l2cap_sock_new_connection_cb()` when a NULL pointer is dereferenced without proper validation. The fix applies a NULL guard pattern already implemented in related callback functions `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. This vulnerability could potentially lead to kernel crashes or denial of service conditions when processing Bluetooth L2CAP connection requests. The issue was resolved by adding appropriate NULL pointer checks before dereferencing. Multiple stable kernel branches received backported fixes.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Linux system administrators managing Bluetooth-enabled systems, embedded device manufacturers using Bluetooth connectivity, kernel maintainers, and security teams tracking kernel-level Bluetooth vulnerabilities.
Technical summary
The vulnerability is a null-pointer dereference in `l2cap_sock_new_connection_cb()` within the Linux kernel's Bluetooth L2CAP implementation. The callback function fails to validate a pointer before dereferencing, leading to a potential kernel oops or crash. The resolution adds a NULL guard check consistent with defensive patterns already present in `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. The fix has been backported to multiple stable kernel branches as evidenced by five separate kernel.org stable commits.
Defensive priority
medium
Recommended defensive actions
- Apply kernel updates from distribution vendors when available
- Monitor stable kernel releases for backported fixes
- Review Bluetooth L2CAP handling in custom kernel builds
- Validate Bluetooth stack configurations on affected systems
Evidence notes
CVE description confirms null-pointer-dereference in Bluetooth L2CAP socket callback. Fix pattern replicates existing guards in `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. Five kernel.org stable commit references indicate backports across multiple kernel versions. NVD status shows 'Awaiting Analysis' with no CVSS assigned. No KEV listing or known ransomware campaign use.
Official resources
-
CVE-2026-45835 CVE record
CVE.org
-
CVE-2026-45835 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
2026-05-26