HomeDefectsLIN1022-34313
Fixed

LIN1022-34313 : Security Advisory - linux - CVE-2026-97977

Created: Sep 25, 2026    Updated: Sep 29, 2026
Resolved Date: Sep 26, 2026
Found In Version: 10.22.33.2
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: btusb: Fix UAF of btusb_data by rx_work  btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.  btusb_disconnect() calls hci_unregister_dev(), which invokes btusb_close(), and then frees the btusb_data. A still running btusb_rx_work() then dereferences the freed data:  	while ((skb = skb_dequeue(&data->acl_q))) 		data->recv_acl(data->hdev, skb);  Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also has to happen after btusb_stop_traffic(), otherwise an URB completion racing with the cancel can requeue the work right after it has been waited for.
Data source: kernel.org (416baaa9-dc9f-4396-8d5f-8c081fb06d67)

CVEs