CVE-2026-46056

Source
https://cve.org/CVERecord?id=CVE-2026-46056
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46056.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46056
Downstream
Related
Published
2026-05-27T12:57:15.150Z
Modified
2026-06-05T18:29:24.971319475Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_event: fix potential UAF in SSP passkey handlers

hciconn lookup and field access must be covered by hdev lock in hciuserpasskeynotifyevt() and hcikeypressnotifyevt(), otherwise the connection can be freed concurrently.

Extend the hcidevlock critical section to cover all conn usage in both handlers.

Keep the existing keypress notification behavior unchanged by routing the early exits through a common unlock path.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46056.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
92a25256f142d55e25f9959441cea6ddeabae57e
Fixed
b6ae482f88654db407c8c17619d4b62959b903ef
Fixed
204028af77a265e31ceb4ba7f643349a3cca72b2
Fixed
01a6431766c35dfedb86e0cb5d3fc80c6d604a47
Fixed
e08d75753db17aa943d7622f09d9c217b5bfd3b8
Fixed
8c6443bb9257b780986fb67ec08565bf48ecb8d7
Fixed
85fa3512048793076eef658f66489112dcc91993

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46056.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.140
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.86
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.27
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46056.json"