In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources.
Change the function to return -EEXIST if queue item already exists.
Modify all callsites to handle that.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 1, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-tegraUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-6.8.0-1036-nvidia-tegraUpgrade linux-image-nvidia-tegra-rtUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-6.8.0-1036-nvidia-tegra-rt | May 25, 2026 | May 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub