CVE-2026-74537 PUBLISHED

Bluetooth: ISO: hold sk properly in iso_conn_ready

Assigner: Linux
Reserved: 15.08.2026 Published: 15.08.2026 Updated: 15.08.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: hold sk properly in iso_conn_ready

sk deref in iso_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk is currently accessed without either:

<pre>[Task 1] [Task 2] iso_sock_release iso_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) iso_sock_kill(sk) UAF on sk deref </pre>

Fix possible UAF by holding sk refcount in iso_conn_ready(). Also recheck after lock_sock that the socket is still valid. Adjust locking so conn->sk is cleared only under lock_sock.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 27c24fda62b601d6f9ca5e992502578c4310876f to 4e9b5e8669b3602a4e01b6d1e9539b72e42c84d5 (excl.)
  • affected from 27c24fda62b601d6f9ca5e992502578c4310876f to 1308d72903d792d10b82bc4ef08b8a4452308b04 (excl.)
  • affected from 27c24fda62b601d6f9ca5e992502578c4310876f to 0d255e63fcf3f13a570d7ac11678fa1164ac015c (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.15 is affected
  • unaffected from 0 to 5.15 (excl.)
  • unaffected from 6.18.44 to 6.18.* (incl.)
  • unaffected from 7.1.8 to 7.1.* (incl.)
  • unaffected from 7.2-rc6 to * (incl.)

References