CVE-2026-64144

Source
https://cve.org/CVERecord?id=CVE-2026-64144
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64144.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64144
Downstream
Published
2026-07-19T15:40:36.041Z
Modified
2026-07-21T03:47:51.627058732Z
Summary
Bluetooth: btmtk: fix urb->setup_packet leak in error paths
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtk: fix urb->setup_packet leak in error paths

The setuppacket of control urb is not freed if usbsubmit_urb fails or the submitted urb is killed. Add free in these two paths.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64144.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a1c49c434e15050b5dafe3b6f5cc732d4f02d657
Fixed
2a1905730e0c771b999906a7b509722f795563c6
Fixed
68c027c2003b0a8a1439d0301c59c6fd1eb3b844
Fixed
a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c
Fixed
0d2572bafea33c7cd1d77c6a25f25ff31a432482
Fixed
dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64144.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64144.json"