8.8

CVE-2026-31408

Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold

sco_recv_frame() reads conn->sk under sco_conn_lock() but immediately
releases the lock without holding a reference to the socket. A concurrent
close() can free the socket between the lock release and the subsequent
sk->sk_state access, resulting in a use-after-free.

Other functions in the same file (sco_sock_timeout(), sco_conn_del())
correctly use sco_sock_hold() to safely hold a reference under the lock.

Fix by using sco_sock_hold() to take a reference before releasing the
lock, and adding sock_put() on all exit paths.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d57384e27d1ebf0047e3f00a6e1181b8be9857a2
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < b0a7da0e3f7442545f071499beb36374714bb9de
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 45aaca995e4a7a05b272a58e7ab2fff4f611b8f1
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 108b81514d8f2535eb16651495cefb2250528db3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < e76e8f0581ef555eacc11dbb095e602fb30a5361
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 598dbba9919c5e36c54fe1709b557d64120cb94b
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.15.*
Version 5.15.203
Status unaffected
Version <= 6.1.*
Version 6.1.168
Status unaffected
Version <= 6.6.*
Version 6.6.131
Status unaffected
Version <= 6.12.*
Version 6.12.80
Status unaffected
Version <= 6.18.*
Version 6.18.21
Status unaffected
Version <= 6.19.*
Version 6.19.11
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.087
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.