SB20260917188 - Use-after-free in Linux kernel bluetooth
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89774)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free in the Bluetooth SCO socket connection handling code when handling SCO connection-ready events concurrently with socket closure. A remote attacker can trigger a race between connection setup and socket release to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39
- https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8
- https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
- https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc
- https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277
- https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2