CVE-2026-98293 PUBLISHED

Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()

iso_get_sock() returns the parent socket with a reference held, which is dropped by sock_put() once the child socket has been set up. The error path taken when iso_sock_alloc() fails only calls release_sock() and returns, leaking the reference and thus the parent socket itself.

Drop the reference on that path as well.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 11dc486ed5d4626e6b92a23b67ed76cb6c48bfc9 to ea8a262662be62c095789924c11722ecbf40a4de (excl.)
  • affected from fa224d0c094a458e9ebf5ea9b1c696136b7af427 to 9228f87365e68a6cae191f57f456e89a6d2167cf (excl.)
  • affected from fa224d0c094a458e9ebf5ea9b1c696136b7af427 to e2b156a8d25966be49c1f809b654a2c4bb16564d (excl.)
  • affected from fa224d0c094a458e9ebf5ea9b1c696136b7af427 to f016daabd4fec4e9b8563f8b6f42eabce0ca66b0 (excl.)
  • affected from fa224d0c094a458e9ebf5ea9b1c696136b7af427 to ca18ee413a7cb6f09885778039225e58bae0d607 (excl.)
  • affected from 6.6.67 to 6.6.158 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References