PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45835 Linux CVE debrief

A null-pointer dereference vulnerability exists in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) subsystem. The flaw occurs in `l2cap_sock_new_connection_cb()` when a NULL pointer is dereferenced without proper validation. The fix applies a NULL guard pattern already implemented in related callback functions `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. This vulnerability could potentially lead to kernel crashes or denial of service conditions when processing Bluetooth L2CAP connection requests. The issue was resolved by adding appropriate NULL pointer checks before dereferencing. Multiple stable kernel branches received backported fixes.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-06-26
Advisory published
2026-05-26
Advisory updated
2026-06-26

Who should care

Linux system administrators managing Bluetooth-enabled systems, embedded device manufacturers using Bluetooth connectivity, kernel maintainers, and security teams tracking kernel-level Bluetooth vulnerabilities.

Technical summary

The vulnerability is a null-pointer dereference in `l2cap_sock_new_connection_cb()` within the Linux kernel's Bluetooth L2CAP implementation. The callback function fails to validate a pointer before dereferencing, leading to a potential kernel oops or crash. The resolution adds a NULL guard check consistent with defensive patterns already present in `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. The fix has been backported to multiple stable kernel branches as evidenced by five separate kernel.org stable commits.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel updates from distribution vendors when available
  • Monitor stable kernel releases for backported fixes
  • Review Bluetooth L2CAP handling in custom kernel builds
  • Validate Bluetooth stack configurations on affected systems

Evidence notes

CVE description confirms null-pointer-dereference in Bluetooth L2CAP socket callback. Fix pattern replicates existing guards in `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. Five kernel.org stable commit references indicate backports across multiple kernel versions. NVD status shows 'Awaiting Analysis' with no CVSS assigned. No KEV listing or known ransomware campaign use.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45835 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45835

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45835 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45835

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0a120d96166301d7a95be75b52f843837dbd1219

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/741e6024e31587b0c021b6616a9e428a4ea0b64a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/76083fb80f5a38ac13326b2d810f66bd07771eea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ab77c8bc30269bee15d917059a66bea48909f5f0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bc3bb9f40da8e53896abc2d29c6d0c6686fe4ab9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.