Use-after-free in Linux kernel - CVE-2026-74535
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free and deadlock condition in iso_sock_timeout in the Bluetooth ISO subsystem when handling socket timeout work concurrently with connection deletion or synchronously disabling delayed work while holding the socket lock. A local user can trigger socket timeout handling and connection teardown to cause a denial of service.
The issue involves a race between timeout processing and connection deletion in Bluetooth ISO sockets.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74535
linux (Debian package) - update to 6.12.105-1