-

CVE-2026-74536

Bluetooth: ISO: fix leaking sk after socket release

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: fix leaking sk after socket release

iso_sock_kill() tests !sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket ||
sock_flag(sk, SOCK_DEAD) for early return, but this is always true since
sock_orphan(sk) sets SOCK_DEAD, so the sk reference released by socket
always leaks, iso_sock_destruct is never called.

The socket reference also leaks when __iso_sock_close() does not set
SOCK_ZAPPED, since iso_conn_del() does not call iso_sock_kill() after
zapping.

Fix by replacing SOCK_DEAD by BT_SK_KILLED flag that is not used for
something else, and lock_sock to ensure iso_sock_kill() puts sk only
after socket release only once. Release and iso_conn_del may run
concurrently. Call iso_sock_kill() from iso_conn_del() to clean sk up
after zapping.

Remove call to iso_sock_kill() from iso_sock_close(), as it's generally
no-op there.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 96ed3c772c08e7a91c399567f412618e43231023
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < e76a0ae6542ae43241b2147bacf4990e7ae5316a
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < e30e5ca63c8fbe3cd505fbb419bb547760cda633
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < ce57442a379212fe3fda59c9437ee8217eceb5b1
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/96ed3c772c08e7a91c399567f412618e43231023
https://git.kernel.org/stable/c/e76a0ae6542ae43241b2147bacf4990e7ae5316a
https://git.kernel.org/stable/c/e30e5ca63c8fbe3cd505fbb419bb547760cda633
https://git.kernel.org/stable/c/ce57442a379212fe3fda59c9437ee8217eceb5b1