Junglewise Threat Intelligence

CVE-2026-53276: Linux Kernel use-after-free in Bluetooth ISO socket rebinding

CVE-2026-53276 · Severity: info · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to a system crash or unpredictable behavior. The issue occurs when the system handles Bluetooth ISO connections, where a specific internal reference might be accessed after it has already been deleted by another process. This could potentially be exploited by a local attacker to cause a denial of service.

Technical details

A use-after-free vulnerability exists in net/bluetooth/iso.c within the iso_sock_rebind_bc() function. The vulnerability is caused by a race condition where the 'bis' pointer (hci_conn) is cached before the socket lock is released. During the window where the lock is dropped to acquire hci_dev_lock, a concurrent close() operation can destroy the connection and free the underlying structure. When the kernel subsequently attempts to access bis->hdev, it performs a use-after-free access. The fix involves using a safely acquired hdev reference via iso_conn_get_hdev() instead of accessing it through the potentially freed bis pointer.

Affected products

  • Linux Linux Kernel 6.19 to 7.0.13

Timeline

  • 2026-06-01: other: Patch authored
  • 2026-06-25: disclosed: CVE published

References

Related threats