What is CVE-2026-11894?
CVE-2026-11894 is a vulnerability in the Realtek BEE Bluetooth HCI driver's `bt_hci_bee_send()` function, which violates the buffer-ownership contract by not properly consuming the `net_buf` on error returns. This affects systems using the affected driver and could lead to resource management issues. Applying the relevant patch or updating the driver is recommended.
Azərbaycanca: CVE-2026-11894, Realtek BEE Bluetooth HCI sürücüsündəki `bt_hci_bee_send()` funksiyasında bufer sahibliyi müqaviləsinin pozulması ilə bağlı zəiflikdir. Bu, ötürmə zamanı xəta baş verdikdə `net_buf`-un sərbəst buraxılmamasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə Realtek BEE sürücüsündən istifadə edən cihazlar üçün yamaq tətbiq edilməli və ya sürücü yenilənməlidir.
FAQ2
In which driver and function does CVE-2026-11894 occur?
The vulnerability lies in the Realtek BEE Bluetooth HCI driver's `bt_hci_bee_send()` function.
What is recommended to mitigate CVE-2026-11894?
It is recommended to apply the relevant patch or update the Realtek BEE driver for affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.