PT-2026-89084 · Linux · Linux
CVE-2026-80914
·
Published
2026-09-09
·
Updated
2026-09-10
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: fix use-after-free of listener socket in iso conn ready
iso conn ready() looks up the BIS listener socket with iso get sock(),
which takes a reference, and then, without re-checking its state,
creates a child socket from it:
parent = iso get sock(hdev, ...);
if (!parent)
return;
lock sock(parent);
sk = iso sock alloc(sock net(parent), NULL, BTPROTO ISO, ...);
...
iso chan add(conn, sk, parent);
...
release sock(parent);
sock put(parent);
If the listener socket is closed concurrently, between iso get sock()
and lock sock(), the reference taken by iso get sock() may be the last
one: the close path drops the link-list reference, and once
iso conn ready() drops its own reference at the end of the function the
socket is freed. The child socket, however, is already linked to the
freed parent, and a later disconnect of the child runs iso chan del()
-> bt accept unlink(), which dereferences the dangling parent pointer
into the freed accept queue (a use-after-free). The same dangling
pointer is also dereferenced through parent->***() in
iso chan del().
Fix it the same way the connected (non-BIS) path was fixed in commit
0d255e63fcf3 ("Bluetooth: ISO: hold sk properly in iso conn ready"):
after taking the socket lock, re-check that the parent is still a
listening, alive socket, and bail out otherwise.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux