Junglewise Threat Intelligence

CVE-2026-63871: Linux Kernel data race in Bluetooth ISO hci_get_route

CVE-2026-63871 · Severity: info · CVSS 4.4 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to system instability. The issue occurs when multiple processes attempt to modify Bluetooth socket settings simultaneously, potentially causing a race condition. This could result in a system crash or unpredictable behavior during Bluetooth operations.

Technical details

A data race exists in the Bluetooth ISO implementation within the Linux kernel. The functions iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() call hci_get_route() using fields from iso_pi(sk) (specifically dst, src, and src_type) without holding the necessary socket lock (lock_sock()). These fields can be modified concurrently by other system calls like connect() or setsockopt(), leading to a race condition detected by KCSAN. An attacker with local access could potentially exploit this race to cause kernel memory corruption or a system crash. The fix involves snapshotting the required fields while holding the socket lock before they are used.

Affected products

  • Linux Linux 6.1.9 to 7.1

Timeline

  • 2026-06-01: other: Vulnerability fixed in kernel source
  • 2026-07-19: disclosed: CVE published

References