Junglewise Threat Intelligence

CVE-2026-80683: Linux kernel Bluetooth SCO use-after-free in sco_conn_del()

CVE-2026-80683 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth SCO (Synchronous Connection Oriented) subsystem contains a use-after-free vulnerability in connection handling that can occur when socket close races with controller disconnect events. An attacker with local access or the ability to manipulate Bluetooth connections could exploit this to cause a kernel crash or potentially execute arbitrary code, affecting the stability and security of systems with Bluetooth capabilities.

Technical details

The vulnerability is a use-after-free (CWE-416) in the sco_conn_del() function in the Linux kernel's Bluetooth SCO implementation. The root cause is improper reference counting: the socket borrows a connection reference without holding its own, leading to mismatched reference increments and decrements. When close() races with the controller's Disconnection Complete event, sco_chan_del() clears the socket pointer and drops the reference while sco_conn_del() is running. The subsequent reference put operations access freed memory. The fix requires giving the socket its own reference via __sco_chan_add() and ensuring all reference holders are explicit and properly balanced. This is a local/adjacent vector vulnerability affecting any system with Bluetooth enabled; no authentication or network access is required for local exploitation.

Affected products

  • Linux Linux kernel Affected versions unspecified in advisory

Timeline

  • 2026-08-28: disclosed

Related threats