CVE-2026-74531
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in abort_conn_sync() There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.
- Published Aug 15, 2026
- CVSS 8.8 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available