SB2026090605 - Use of uninitialized resource in Linux kernel bluetooth



SB2026090605 - Use of uninitialized resource in Linux kernel bluetooth

Published: September 6, 2026

Security Bulletin ID SB2026090605
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use of uninitialized resource (CVE-ID: CVE-2026-80761)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized stack memory in the Bluetooth ISO socket getname handler when returning socket address information through getsockname(2) or getpeername(2). A local user can open a BTPROTO_ISO socket and invoke getsockname(2) to disclose sensitive information.

The larger disclosure involving broadcast-peer address fields requires an established BIS or PA connection.


Remediation

Install update from vendor's website.