๐Ÿ” CVE Alert

CVE-2026-74534

UNKNOWN 0.0

Bluetooth: ISO: fix refcounting of iso_conn

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn iso_conn_del() and iso_chan_del() have a race that results to double-put of iso_conn: [Task hdev->workqueue] [Task 2] iso_conn_del iso_chan_del iso_conn_hold_unless_zero iso_conn_lock iso_conn_lock conn->sk = NULL iso_conn_unlock sk = iso_sock_hold(conn) <---------ยด if (!sk) iso_conn_put iso_conn_put iso_conn_put /* UAF */ The extra put for !sk in iso_conn_del() is currently required since failing iso_chan_add() may leave iso_conn not associated with any sk. Fix by having iso_pi(sk)->conn own refcount when non-NULL, so iso_conn_del does not need to put it. Adjust the iso_conn_add() refcounting so that conn is put if it does not get associated with an sk.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
dc26097bdb864a0d5955b9a25e43376ffc1af99b < 3b921533e8aa95b77aadcf31737595578e735f3c dc26097bdb864a0d5955b9a25e43376ffc1af99b < 8208b4939afb0a1977fffe902c3ca42fe0f3baaa dc26097bdb864a0d5955b9a25e43376ffc1af99b < fdfde532ab1caa165fcd8985001157ac8b4db365 f53e7489273dc2bb307bf50f319b3762d45534f0 a58d0f5dac322e16cc75334d000666512341bde5 6.11.11 < 6.12 6.12.2 < 6.13
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3b921533e8aa95b77aadcf31737595578e735f3c git.kernel.org: https://git.kernel.org/stable/c/8208b4939afb0a1977fffe902c3ca42fe0f3baaa git.kernel.org: https://git.kernel.org/stable/c/fdfde532ab1caa165fcd8985001157ac8b4db365