๐Ÿ” CVE Alert

CVE-2026-74533

UNKNOWN 0.0

Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero hci_conn::iso_data is accessed and modified without lock or RCU. This leads to a race [Task hdev->workqueue] [Task 2] iso_recv iso_conn_put(conn) conn = LOAD hcon->iso_data iso_conn_free(conn) iso_conn_hold_unless_zero(conn) hcon->iso_data = NULL kfree(conn) kref_get_unless_zero(&conn->ref) /* UAF */ and also to races in iso_conn_add() vs. iso_conn_free(). Fix by adding spinlock hci_conn::proto_lock and using it to guard hci_conn::iso_data.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
dc26097bdb864a0d5955b9a25e43376ffc1af99b < 876a3e94c70d0859d1dad1c986112d4f0d99eba8 dc26097bdb864a0d5955b9a25e43376ffc1af99b < af24e338bf5dafb80f42baa9a0b9e9b57b1c5d9c f53e7489273dc2bb307bf50f319b3762d45534f0 a58d0f5dac322e16cc75334d000666512341bde5 6.11.11 < 6.12 6.12.2 < 6.13
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/876a3e94c70d0859d1dad1c986112d4f0d99eba8 git.kernel.org: https://git.kernel.org/stable/c/af24e338bf5dafb80f42baa9a0b9e9b57b1c5d9c