CVE-2026-89774

Summary

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state:

[Task 1]            [Task 2]
                    sco_sock_release
sco_conn_ready
  sk = conn->sk
                      lock_sock(sk)
                        conn->sk = NULL
  lock_sock(sk)
                      release_sock(sk)
                      sco_sock_kill(sk)
   UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < 50aae396dc30377bec8e3b181b8346f8fd38f7d8affected
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < 6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1affected
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < d141d9b769bcd1b747898528c5023270cda040f2affected
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < 73cb063f5ec6ca51eb1e246c6d332563002ac277affected
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < 7199c78c3a3e399a4dc439d845826793880ccedcaffected
LinuxLinux27c24fda62b601d6f9ca5e992502578c4310876f < 4e37f6452d586b95c346a9abdd2fb80b67794f39affected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References