Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to system instability. The issue occurs when multiple processes attempt to modify Bluetooth socket settings simultaneously, potentially causing a race condition. This could result in a system crash or unpredictable behavior during Bluetooth operations.
Technical details
A data race exists in the Bluetooth ISO implementation within the Linux kernel. The functions iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() call hci_get_route() using fields from iso_pi(sk) (specifically dst, src, and src_type) without holding the necessary socket lock (lock_sock()). These fields can be modified concurrently by other system calls like connect() or setsockopt(), leading to a race condition detected by KCSAN. An attacker with local access could potentially exploit this race to cause kernel memory corruption or a system crash. The fix involves snapshotting the required fields while holding the socket lock before they are used.
Affected products
- Linux Linux 6.1.9 to 7.1
Timeline
- 2026-06-01: other: Vulnerability fixed in kernel source
- 2026-07-19: disclosed: CVE published