CVE-2026-74538 PUBLISHED

Bluetooth: ISO: lock sk in iso_connect_ind

Assigner: Linux
Reserved: 15.08.2026 Published: 15.08.2026 Updated: 15.08.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: lock sk in iso_connect_ind

Accessing iso_pi(sk)->conn requires lock_sock, which is not taken in the "ev3" part of iso_connect_ind. It may also be NULL if socket has transitioned away from the LISTEN/CONNECT states before locking.

Fix by adding lock/release. Recheck hcon is valid after lock acquire where needed.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb to e8e9cff6d80eeec28dec4cf7cc18662986945391 (excl.)
  • affected from 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb to 9bee7e476534f27e830658dad962d85da9edf6bf (excl.)
  • affected from 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb to 4311fd6f429065a8ba208660360a895627a00cf3 (excl.)
  • Version 489efc9ae36f164423f5fa7ace772a7ab8131cd8 is affected
  • affected from 6.8.9 to 6.9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.9 is affected
  • unaffected from 0 to 6.9 (excl.)
  • unaffected from 6.18.44 to 6.18.* (incl.)
  • unaffected from 7.1.8 to 7.1.* (incl.)
  • unaffected from 7.2-rc6 to * (incl.)

References