Junglewise Threat Intelligence

CVE-2026-31408: Linux Kernel use-after-free in Bluetooth SCO sco_recv_frame

CVE-2026-31408 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's Bluetooth subsystem. This flaw could allow an attacker to cause a system crash or potentially execute unauthorized code by exploiting how the system handles Bluetooth audio (SCO) connections. The issue occurs when the system tries to access a communication socket that has already been closed and deleted from memory.

Technical details

A use-after-free vulnerability exists in net/bluetooth/sco.c within the sco_recv_frame() function. The root cause is a race condition where the function reads a socket pointer (conn->sk) under a lock but releases the lock without incrementing the socket's reference count via sock_hold(). A concurrent close() operation can free the socket before the function accesses sk->sk_state, leading to a use-after-free. An attacker within Bluetooth range could potentially exploit this to trigger a kernel panic or achieve escalated privileges. The issue has been resolved by implementing proper reference counting using sco_sock_hold() and sock_put() across all exit paths.

Affected products

  • Linux Linux Kernel from 2.6.12-rc2 up to 6.19.11

Timeline

  • 2026-04-06: advisory: Initial disclosure of CVE-2026-31408
  • 2026-04-02: patched: Fixes committed to various stable kernel branches

References

Related threats