Use of uninitialized resource in Linux kernel - CVE-2026-80761
Published: September 6, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of uninitialized stack memory in the Bluetooth ISO socket getname handler when returning socket address information through getsockname(2) or getpeername(2). A local user can open a BTPROTO_ISO socket and invoke getsockname(2) to disclose sensitive information.
The larger disclosure involving broadcast-peer address fields requires an established BIS or PA connection.