A vulnerability was found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. It has been classified as very critical. Impacted is the function
pending_eir_or_class of the component Bluetooth. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-74511. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.