{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89774","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.765Z","datePublished":"2026-09-16T08:24:21.248Z","dateUpdated":"2026-09-16T14:38:26.042Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:38:26.042Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: hold sk properly in sco_conn_ready\n\nsk deref in sco_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. conn->sk and parent sk is\ncurrently accessed without either, and without checking parent->sk_state:\n\n    [Task 1]            [Task 2]\n                        sco_sock_release\n    sco_conn_ready\n      sk = conn->sk\n                          lock_sock(sk)\n                            conn->sk = NULL\n      lock_sock(sk)\n                          release_sock(sk)\n                          sco_sock_kill(sk)\n       UAF on sk deref\n\nand similarly for access to sco_get_sock_listen() return value.\n\nFix possible UAF by holding sk refcount in sco_conn_ready() and making\nsco_get_sock_listen() increase refcount. Also recheck after lock_sock\nthat the socket is still valid.  Adjust conn->sk locking so it's\nprotected also by lock_sock() of the associated socket if any."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - sco_conn_ready runs from sco_connect_cfm via hci_connect_cfm on HCI Connection Complete, Synchronous Connection Complete, and deferred Connection Request for SCO/eSCO, driven by an in-range Bluetooth peer. Kernel CNA guidance classifies Bluetooth as Adjacent.\nAC:L - This is a use-after-free race between sco_conn_ready and sco_sock_release/sco_sock_kill. An attacker who times HCI SCO completion against socket close (rapid peer establish/teardown or concurrent connect/close) controls both sides and can retry until the window is hit; CONFIG_BT_BREDR defaults to y.\nPR:N - Incoming SCO is accepted when any listen socket exists (typical HFP/audio daemons on phones) with no Linux credentials required of the peer. sco_sock_create has no capability check, and listener close can occur from automatic bluetoothd/PipeWire teardown during connection setup.\nUI:N - No victim action is required at exploit time. OS Bluetooth audio stacks keep SCO listeners and manage sockets during normal headset, hands-free, and automotive operation while peer-initiated SCO/eSCO traffic is processed.\nS:U - The use-after-free corrupts in-kernel Bluetooth socket memory and can enable privilege escalation within the same host kernel security authority. It does not cross a VM, container, or IOMMU boundary.\nC:H - Use-after-free of struct sock after sco_sock_kill lets an attacker reclaim the freed slab object and read kernel memory through subsequent sock operations, which per CNA guidance is High confidentiality impact.\nI:H - sco_conn_ready writes sk->sk_state and makes an indirect call through sk->sk_state_change on the freed sock, a standard kernel heap UAF primitive for arbitrary write and control-flow hijack, scored High per UAF guidance.\nA:H - lock_sock and subsequent sk field access on a freed socket cause a kernel oops or panic. Per CNA guidance any use-after-free is High availability impact even before full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/sco.c"],"versions":[{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"50aae396dc30377bec8e3b181b8346f8fd38f7d8","status":"affected","versionType":"git"},{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1","status":"affected","versionType":"git"},{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"d141d9b769bcd1b747898528c5023270cda040f2","status":"affected","versionType":"git"},{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"73cb063f5ec6ca51eb1e246c6d332563002ac277","status":"affected","versionType":"git"},{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"7199c78c3a3e399a4dc439d845826793880ccedc","status":"affected","versionType":"git"},{"version":"27c24fda62b601d6f9ca5e992502578c4310876f","lessThan":"4e37f6452d586b95c346a9abdd2fb80b67794f39","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/sco.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8"},{"url":"https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1"},{"url":"https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2"},{"url":"https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277"},{"url":"https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc"},{"url":"https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39"}],"title":"Bluetooth: SCO: hold sk properly in sco_conn_ready","x_generator":{"engine":"bippy-1.2.0"}}}}