8.8
CVE-2026-63946
- EPSS 0.33%
- Veröffentlicht 19.07.2026 14:55:40
- Zuletzt bearbeitet 27.07.2026 17:44:23
- CVE-Watchlists
- Unerledigt
Bluetooth: ISO: fix UAF in iso_recv_frame
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_recv_frame reads conn->sk under iso_conn_lock but releases the lock before using sk, with no reference held. A concurrent iso_sock_kill() can free sk in that window, causing use-after-free on sk->sk_state and sock_queue_rcv_skb(). Fix by replacing the bare pointer read with iso_sock_hold(conn), which calls sock_hold() while the spinlock is held, atomically elevating the refcount before the lock drops. Add a drop_put label so sock_put() is called on all exit paths where the hold succeeded.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
c57ea90f203c8b8b41a474f19a09000d0f841436
Status
affected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
119fb6f80c44dc1c65d604cf28e64c56bd9b6568
Status
affected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
b04ec131325baf4ea4577d6c6e6b86cf092e3731
Status
affected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
c318aa51830a3d2cc1229968fe521441c97356cd
Status
affected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
1a6b803b00ccdd7666506adbe01ddae1c72d1ca9
Status
affected
Version
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version <
47f23a259517abbdb8032c057a1e8a6bf3734878
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.0
Status
affected
Version
0
Version <
6.0
Status
unaffected
Version <=
6.1.*
Version
6.1.176
Status
unaffected
Version <=
6.6.*
Version
6.6.143
Status
unaffected
Version <=
6.12.*
Version
6.12.93
Status
unaffected
Version <=
6.18.*
Version
6.18.35
Status
unaffected
Version <=
7.0.*
Version
7.0.12
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.251 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/c57ea90f203c8b8b41a474f19a09000d0f841436
https://git.kernel.org/stable/c/119fb6f80c44dc1c65d604cf28e64c56bd9b6568
https://git.kernel.org/stable/c/b04ec131325baf4ea4577d6c6e6b86cf092e3731
https://git.kernel.org/stable/c/c318aa51830a3d2cc1229968fe521441c97356cd
https://git.kernel.org/stable/c/1a6b803b00ccdd7666506adbe01ddae1c72d1ca9
https://git.kernel.org/stable/c/47f23a259517abbdb8032c057a1e8a6bf3734878