Linuxカーネルにおいて、以下の脆弱性が修正されました。Bluetoothのhci_eventにおいて、SSPパスキーハンドラでの潜在的な解放後使用(UAF)問題を修正しました。hci_user_passkey_notify_evt()およびhci_keypress_notify_evt()内で、hci_connの検索およびフィールドアクセスはhdevロックで保護する必要があります。そうしなければ接続が同時に解放される可能性があります。両ハンドラのすべてのconn使用をカバーするために、hci_dev_lockのクリティカルセクションを拡張しました。早期終了を共通のアンロックパスにルーティングすることで、既存のキー押下通知の動作を変更せずに維持しています。
Linux Linux Kernel 3.7 以上 6.1.175 未満 Linux Kernel 6.13 以上 6.18.27 未満 Linux Kernel 6.19 以上 7.0.4 未満 Linux Kernel 6.2 以上 6.6.140 未満 Linux Kernel 6.7 以上 6.12.86 未満
・当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。 ・当該ソフトウェアが扱う全ての情報が書き換えられる可能性があります。 ・当該ソフトウェアが完全に停止する可能性があります。
リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
解放済みメモリの使用(CWE-416) [NVD評価]
CVE-2026-46056
National Vulnerability Database (NVD) : CVE-2026-46056 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/204028af77a265e31ceb4ba7f643349a3cca72b2) 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/b6ae482f88654db407c8c17619d4b62959b903ef) 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/85fa3512048793076eef658f66489112dcc91993) 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/8c6443bb9257b780986fb67ec08565bf48ecb8d7) 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/01a6431766c35dfedb86e0cb5d3fc80c6d604a47) 関連文書 : Bluetooth: hci_event: fix potential UAF in SSP passkey handlers - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/e08d75753db17aa943d7622f09d9c217b5bfd3b8)
[2026年06月17日] 掲載