8.8

CVE-2026-89774

Bluetooth: SCO: hold sk properly in sco_conn_ready

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk and parent sk is
currently accessed without either, and without checking parent->sk_state:

    [Task 1]            [Task 2]
                        sco_sock_release
    sco_conn_ready
      sk = conn->sk
                          lock_sock(sk)
                            conn->sk = NULL
      lock_sock(sk)
                          release_sock(sk)
                          sco_sock_kill(sk)
       UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making
sco_get_sock_listen() increase refcount. Also recheck after lock_sock
that the socket is still valid.  Adjust conn->sk locking so it's
protected also by lock_sock() of the associated socket if any.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < 50aae396dc30377bec8e3b181b8346f8fd38f7d8
Status affected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < 6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
Status affected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < d141d9b769bcd1b747898528c5023270cda040f2
Status affected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < 73cb063f5ec6ca51eb1e246c6d332563002ac277
Status affected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < 7199c78c3a3e399a4dc439d845826793880ccedc
Status affected
Version 27c24fda62b601d6f9ca5e992502578c4310876f
Version < 4e37f6452d586b95c346a9abdd2fb80b67794f39
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.09
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8
https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2
https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277
https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc
https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39