Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72336

Published Aug 15, 2026 EPSS 0.20% (10th pctl)

Overview

CVE-2026-72336 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: 6lowpan: hold L2CAP conn across debugfs control

get_l2cap_conn() looks up an LE hci_conn under hdev protection, but

then drops that protection before reading hcon->l2cap_data and before

lowpan_control_write() later dereferences conn->hcon. A disconnect or

device close can tear down the same L2CAP connection in that window.

The buggy scenario involves two paths, with each column showing the order

within that path:

6LoWPAN control write: HCI disconnect/device close:

1. get_l2cap_conn() finds hcon 1. hci_disconn_cfm() dispatches

and hcon->l2cap_data. the L2CAP disconnect callback.

2. get_l2cap_conn() drops hdev 2. l2cap_conn_del() clears

protection and returns conn. hcon->l2cap_data and drops the

L2CAP connection reference.

3. lowpan_control_write() reads 3. hci_conn_del() removes and drops

conn->h

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72336?

CVE-2026-72336 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72336?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72336?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72336?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72336 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.