Executive brief
The Linux kernel's Bluetooth SCO (Synchronous Connection Oriented) subsystem contains a use-after-free vulnerability in connection handling that can occur when socket close races with controller disconnect events. An attacker with local access or the ability to manipulate Bluetooth connections could exploit this to cause a kernel crash or potentially execute arbitrary code, affecting the stability and security of systems with Bluetooth capabilities.
Technical details
The vulnerability is a use-after-free (CWE-416) in the sco_conn_del() function in the Linux kernel's Bluetooth SCO implementation. The root cause is improper reference counting: the socket borrows a connection reference without holding its own, leading to mismatched reference increments and decrements. When close() races with the controller's Disconnection Complete event, sco_chan_del() clears the socket pointer and drops the reference while sco_conn_del() is running. The subsequent reference put operations access freed memory. The fix requires giving the socket its own reference via __sco_chan_add() and ensuring all reference holders are explicit and properly balanced. This is a local/adjacent vector vulnerability affecting any system with Bluetooth enabled; no authentication or network access is required for local exploitation.
Affected products
- Linux Linux kernel Affected versions unspecified in advisory
Timeline
- 2026-08-28: disclosed