SB2026090605 - Use of uninitialized resource in Linux kernel bluetooth
Published: September 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2026-80761)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of uninitialized stack memory in the Bluetooth ISO socket getname handler when returning socket address information through getsockname(2) or getpeername(2). A local user can open a BTPROTO_ISO socket and invoke getsockname(2) to disclose sensitive information.
The larger disclosure involving broadcast-peer address fields requires an established BIS or PA connection.
Remediation
Install update from vendor's website.