7.8

CVE-2026-63945

Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock

iso_sock_close() calls iso_sock_clear_timer() before acquiring
lock_sock(sk).

iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the
socket lock held:

    if (!iso_pi(sk)->conn)
        return;
    cancel_delayed_work(&iso_pi(sk)->conn->timeout_work);

Concurrently, iso_conn_del() executes under lock_sock(sk) and calls
iso_chan_del(), which sets iso_pi(sk)->conn to NULL and may result in
the final reference to the connection being dropped:

    CPU0                         CPU1
    ----                         ----
    iso_sock_clear_timer()
      if (conn != NULL) ...      lock_sock(sk)
                                   iso_chan_del()
                                   iso_pi(sk)->conn = NULL
      cancel_delayed_work(conn)  /* NULL deref or UAF */

iso_pi(sk)->conn is not stable across the unlock window, causing a
NULL pointer dereference or use-after-free.

Serialize iso_sock_clear_timer() with the socket lock by moving it
inside lock_sock()/release_sock(), matching the pattern used in
iso_conn_del() and all other call sites.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 35f68f36d9883d56dec21cf85f7556d4657fc393
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 996c2104d0726a8fe584f85b3d6327197374a348
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < bc08c15746f25f41dd0508b25780d1e84acbb2ef
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 4b5f8e608749b7e8fa386c6e4301cf9272595859
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa
https://git.kernel.org/stable/c/35f68f36d9883d56dec21cf85f7556d4657fc393
https://git.kernel.org/stable/c/996c2104d0726a8fe584f85b3d6327197374a348
https://git.kernel.org/stable/c/bc08c15746f25f41dd0508b25780d1e84acbb2ef
https://git.kernel.org/stable/c/51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5
https://git.kernel.org/stable/c/4b5f8e608749b7e8fa386c6e4301cf9272595859