Use of uninitialized resource in Linux kernel - CVE-2026-80761

 

Use of uninitialized resource in Linux kernel - CVE-2026-80761

Published: September 6, 2026


Vulnerability identifier: #VU147156
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80761
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized stack memory in the Bluetooth ISO socket getname handler when returning socket address information through getsockname(2) or getpeername(2). A local user can open a BTPROTO_ISO socket and invoke getsockname(2) to disclose sensitive information.

The larger disclosure involving broadcast-peer address fields requires an established BIS or PA connection.


Affected software

Linux kernel

How to mitigate CVE-2026-80761

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins