A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3/7.2-rc2. Affected by this issue is the function add_device_complete of the file net/bluetooth/mgmt.c of the component Bluetooth Mgmt. Executing a manipulation of the argument flags can lead to use after free.

This vulnerability is registered as CVE-2026-64433. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.