Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to a system crash or unpredictable behavior. The issue occurs when the system handles Bluetooth ISO connections, where a specific internal reference might be accessed after it has already been deleted by another process. This could potentially be exploited by a local attacker to cause a denial of service.
Technical details
A use-after-free vulnerability exists in net/bluetooth/iso.c within the iso_sock_rebind_bc() function. The vulnerability is caused by a race condition where the 'bis' pointer (hci_conn) is cached before the socket lock is released. During the window where the lock is dropped to acquire hci_dev_lock, a concurrent close() operation can destroy the connection and free the underlying structure. When the kernel subsequently attempts to access bis->hdev, it performs a use-after-free access. The fix involves using a safely acquired hdev reference via iso_conn_get_hdev() instead of accessing it through the potentially freed bis pointer.
Affected products
- Linux Linux Kernel 6.19 to 7.0.13
Timeline
- 2026-06-01: other: Patch authored
- 2026-06-25: disclosed: CVE published