8.8

CVE-2026-80914

Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

iso_conn_ready() looks up the BIS listener socket with iso_get_sock(),
which takes a reference, and then, without re-checking its state,
creates a child socket from it:

    parent = iso_get_sock(hdev, ...);
    if (!parent)
        return;

    lock_sock(parent);
    sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...);
    ...
    iso_chan_add(conn, sk, parent);
    ...
    release_sock(parent);
    sock_put(parent);

If the listener socket is closed concurrently, between iso_get_sock()
and lock_sock(), the reference taken by iso_get_sock() may be the last
one: the close path drops the link-list reference, and once
iso_conn_ready() drops its own reference at the end of the function the
socket is freed.  The child socket, however, is already linked to the
freed parent, and a later disconnect of the child runs iso_chan_del()
-> bt_accept_unlink(), which dereferences the dangling parent pointer
into the freed accept queue (a use-after-free).  The same dangling
pointer is also dereferenced through parent->***() in
iso_chan_del().

Fix it the same way the connected (non-BIS) path was fixed in commit
0d255e63fcf3 ("Bluetooth: ISO: hold sk properly in iso_conn_ready"):
after taking the socket lock, re-check that the parent is still a
listening, alive socket, and bail out otherwise.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 1702f12cf59a1c3b670eb6bb4a4d6fcccf07e3b8
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < d47b8f8c02a3d3f282693e5a4ff1f6b4b00518de
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 2387cd06a2c0b416f05028b02bba1089f54c28d9
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 49fd7116f76b860b230843700fb7423ab5331e1f
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 03288b7447c9e572f8ab82fc29cfb4ca719ab210
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 560bef609fa5992745929e8d7d458b9d88dd2830
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.123
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2387cd06a2c0b416f05028b02bba1089f54c28d9
https://git.kernel.org/stable/c/49fd7116f76b860b230843700fb7423ab5331e1f
https://git.kernel.org/stable/c/03288b7447c9e572f8ab82fc29cfb4ca719ab210
https://git.kernel.org/stable/c/560bef609fa5992745929e8d7d458b9d88dd2830
https://git.kernel.org/stable/c/1702f12cf59a1c3b670eb6bb4a4d6fcccf07e3b8
https://git.kernel.org/stable/c/d47b8f8c02a3d3f282693e5a4ff1f6b4b00518de