Executive brief
A security vulnerability has been identified in the Linux kernel's Bluetooth subsystem. This flaw could allow an attacker to cause a system crash or potentially execute unauthorized code by exploiting how the system handles Bluetooth audio (SCO) connections. The issue occurs when the system tries to access a communication socket that has already been closed and deleted from memory.
Technical details
A use-after-free vulnerability exists in net/bluetooth/sco.c within the sco_recv_frame() function. The root cause is a race condition where the function reads a socket pointer (conn->sk) under a lock but releases the lock without incrementing the socket's reference count via sock_hold(). A concurrent close() operation can free the socket before the function accesses sk->sk_state, leading to a use-after-free. An attacker within Bluetooth range could potentially exploit this to trigger a kernel panic or achieve escalated privileges. The issue has been resolved by implementing proper reference counting using sco_sock_hold() and sock_put() across all exit paths.
Affected products
- Linux Linux Kernel from 2.6.12-rc2 up to 6.19.11
Timeline
- 2026-04-06: advisory: Initial disclosure of CVE-2026-31408
- 2026-04-02: patched: Fixes committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/108b81514d8f2535eb16651495cefb2250528db3
- https://git.kernel.org/stable/c/45aaca995e4a7a05b272a58e7ab2fff4f611b8f1
- https://git.kernel.org/stable/c/598dbba9919c5e36c54fe1709b557d64120cb94b
- https://git.kernel.org/stable/c/7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e
- https://git.kernel.org/stable/c/b0a7da0e3f7442545f071499beb36374714bb9de
- https://git.kernel.org/stable/c/d57384e27d1ebf0047e3f00a6e1181b8be9857a2
- https://git.kernel.org/stable/c/e76e8f0581ef555eacc11dbb095e602fb30a5361