CVE-2026-98293
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
iso_get_sock() returns the parent socket with a reference held, which is dropped by sock_put() once the child socket has been set up. The error path taken when iso_sock_alloc() fails only calls release_sock() and returns, leaking the reference and thus the parent socket itself.
Drop the reference on that path as well.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 11dc486ed5d4626e6b92a23b67ed76cb6c48bfc9 < ea8a262662be62c095789924c11722ecbf40a4de | affected |
| Linux | Linux | fa224d0c094a458e9ebf5ea9b1c696136b7af427 < 9228f87365e68a6cae191f57f456e89a6d2167cf | affected |
| Linux | Linux | fa224d0c094a458e9ebf5ea9b1c696136b7af427 < e2b156a8d25966be49c1f809b654a2c4bb16564d | affected |
| Linux | Linux | fa224d0c094a458e9ebf5ea9b1c696136b7af427 < f016daabd4fec4e9b8563f8b6f42eabce0ca66b0 | affected |
| Linux | Linux | fa224d0c094a458e9ebf5ea9b1c696136b7af427 < ca18ee413a7cb6f09885778039225e58bae0d607 | affected |
| Linux | Linux | 6.6.67 < 6.6.158 | affected |
| Linux | Linux | 6.8 | affected |
| Linux | Linux | 0 < 6.8 | unaffected |
| Linux | Linux | 6.6.158 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/ea8a262662be62c095789924c11722ecbf40a4de
- https://git.kernel.org/stable/c/9228f87365e68a6cae191f57f456e89a6d2167cf
- https://git.kernel.org/stable/c/e2b156a8d25966be49c1f809b654a2c4bb16564d
- https://git.kernel.org/stable/c/f016daabd4fec4e9b8563f8b6f42eabce0ca66b0
- https://git.kernel.org/stable/c/ca18ee413a7cb6f09885778039225e58bae0d607
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.