๐Ÿ” CVE Alert

CVE-2026-63945

UNKNOWN 0.0

Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock iso_sock_close() calls iso_sock_clear_timer() before acquiring lock_sock(sk). iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the socket lock held: if (!iso_pi(sk)->conn) return; cancel_delayed_work(&iso_pi(sk)->conn->timeout_work); Concurrently, iso_conn_del() executes under lock_sock(sk) and calls iso_chan_del(), which sets iso_pi(sk)->conn to NULL and may result in the final reference to the connection being dropped: CPU0 CPU1 ---- ---- iso_sock_clear_timer() if (conn != NULL) ... lock_sock(sk) iso_chan_del() iso_pi(sk)->conn = NULL cancel_delayed_work(conn) /* NULL deref or UAF */ iso_pi(sk)->conn is not stable across the unlock window, causing a NULL pointer dereference or use-after-free. Serialize iso_sock_clear_timer() with the socket lock by moving it inside lock_sock()/release_sock(), matching the pattern used in iso_conn_del() and all other call sites.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ccf74f2390d60a2f9a75ef496d2564abb478f46a < d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa ccf74f2390d60a2f9a75ef496d2564abb478f46a < 35f68f36d9883d56dec21cf85f7556d4657fc393 ccf74f2390d60a2f9a75ef496d2564abb478f46a < 996c2104d0726a8fe584f85b3d6327197374a348 ccf74f2390d60a2f9a75ef496d2564abb478f46a < bc08c15746f25f41dd0508b25780d1e84acbb2ef ccf74f2390d60a2f9a75ef496d2564abb478f46a < 51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5 ccf74f2390d60a2f9a75ef496d2564abb478f46a < 4b5f8e608749b7e8fa386c6e4301cf9272595859
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa git.kernel.org: https://git.kernel.org/stable/c/35f68f36d9883d56dec21cf85f7556d4657fc393 git.kernel.org: https://git.kernel.org/stable/c/996c2104d0726a8fe584f85b3d6327197374a348 git.kernel.org: https://git.kernel.org/stable/c/bc08c15746f25f41dd0508b25780d1e84acbb2ef git.kernel.org: https://git.kernel.org/stable/c/51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5 git.kernel.org: https://git.kernel.org/stable/c/4b5f8e608749b7e8fa386c6e4301cf9272595859