Junglewise Threat Intelligence

CVE-2026-89774: Linux kernel Bluetooth SCO use-after-free in sco_conn_ready

CVE-2026-89774 · Severity: high · CVSS 8.8 · Published 2026-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth SCO (Synchronous Connection Oriented) subsystem contains a use-after-free vulnerability in socket handling that allows concurrent operations to free memory while another thread still references it. A local attacker could exploit this race condition to crash the system or potentially execute code with kernel privileges by manipulating Bluetooth socket operations during connection setup.

Technical details

The vulnerability is a use-after-free (UAF) in the sco_conn_ready() function within net/bluetooth/sco.c. The root cause is improper synchronization when dereferencing socket pointers: socket structure (sk) is accessed without holding a reference count or protecting lock, creating a race condition between the connection-ready handler and concurrent socket close operations. An attacker can trigger this by closing a socket in one task while another task processes a SCO connection-ready event, causing dereferenced memory access. The fix adds proper refcount management via sock_hold()/sock_put() and locks socket operations with lock_sock()/release_sock() to serialize access. Attack vector is local (requires ability to open Bluetooth sockets) and no user interaction is required beyond socket operations.

Affected products

  • Linux Linux kernel All versions prior to fix commit 4e37f6452d586b95c346a9abdd2fb80b67794f39

Timeline

  • 2026-09-16: disclosed: Published as CVE-2026-89774
  • 2026-05-06: patched: Commit 4e37f6452d586b95c346a9abdd2fb80b67794f39 merged by Luiz Augusto von Dentz

References

Related threats