Race condition in Linux kernel - CVE-2026-63945
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to a null pointer dereference or use-after-free in iso_sock_clear_timer in the Bluetooth ISO socket handling code when closing a socket concurrently with connection deletion. A local user can trigger concurrent socket operations to cause a denial of service.
How to mitigate CVE-2026-63945
Sources
- https://git.kernel.org/stable/c/35f68f36d9883d56dec21cf85f7556d4657fc393
- https://git.kernel.org/stable/c/4b5f8e608749b7e8fa386c6e4301cf9272595859
- https://git.kernel.org/stable/c/51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5
- https://git.kernel.org/stable/c/996c2104d0726a8fe584f85b3d6327197374a348
- https://git.kernel.org/stable/c/bc08c15746f25f41dd0508b25780d1e84acbb2ef
- https://git.kernel.org/stable/c/d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa