<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:35:45 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351180</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351180</link>
      <description>EUVD-2026-351180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351180</guid>
    </item>
    <item>
      <title>fkie_cve-2026-11894</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11894</link>
      <description>&lt;p&gt;The Realtek BEE Bluetooth HCI driver&amp;#39;s send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and unrefs the buffer itself. The pre-fix code routed all error paths through a shared cleanup label that unconditionally called net_buf_unref(buf) before returning the error code.&lt;/p&gt;
&lt;p&gt;Because the host TX paths (in subsys/bluetooth/host/hci_core.c) unref the buffer again after send() returns an error, the buffer is freed twice: the driver returns it to its net_buf pool and the host then unrefs the already-freed buffer, corrupting the shared pool / underflowing the reference count (CWE-415). The same error branch additionally dereferenced buf-&amp;gt;len inside a LOG_ERR call after the buffer had already been unref&amp;#39;d, a read of freed memory (CWE-416) that is compiled in at the default error log level.&lt;/p&gt;
&lt;p&gt;The failing edges are reached when the controller&amp;#39;s host-to-controller buffer allocation fails or the controller send fails (resource-exhaustion / IO conditions). A remote Bluetooth peer can push the device toward these conditions indirectly by driving heavy host transmit activity, at which point the double-free corrupts the host net_buf pool and most likely crashes the device, with residual potential for further memory corruption. The impact is confined to builds using this specific…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Realtek BEE Bluetooth HCI driver&amp;#39;s send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and unrefs the buffer itself. The pre-fix code routed all error paths through a shared cleanup label that unconditionally called net_buf_unref(buf) before returning the error code.&lt;/p&gt;
&lt;p&gt;Because the host TX paths (in subsys/bluetooth/host/hci_core.c) unref the buffer again after send() returns an error, the buffer is freed twice: the driver returns it to its net_buf pool and the host then unrefs the already-freed buffer, corrupting the shared pool / underflowing the reference count (CWE-415). The same error branch additionally dereferenced buf-&amp;gt;len inside a LOG_ERR call after the buffer had already been unref&amp;#39;d, a read of freed memory (CWE-416) that is compiled in at the default error log level.&lt;/p&gt;
&lt;p&gt;The failing edges are reached when the controller&amp;#39;s host-to-controller buffer allocation fails or the controller send fails (resource-exhaustion / IO conditions). A remote Bluetooth peer can push the device toward these conditions indirectly by driving heavy host transmit activity, at which point the double-free corrupts the host net_buf pool and most likely crashes the device, with residual potential for further memory corruption. The impact is confined to builds using this specific…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-11894</guid>
    </item>
  </channel>
</rss>
