Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk and parent sk is
currently accessed without either, and without checking parent->sk_state:

[Task 1] [Task 2]
sco_sock_release
sco_conn_ready
sk = conn->sk
lock_sock(sk)
conn->sk = NULL
lock_sock(sk)
release_sock(sk)
sco_sock_kill(sk)
UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making
sco_get_sock_listen() increase refcount. Also recheck after lock_sock
that the socket is still valid. Adjust conn->sk locking so it's
protected also by lock_sock() of the associated socket if any.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Patch
AI Analysis

Impact

The problem occurs in the Bluetooth SCO code of the Linux kernel where the socket (sk) is dereferenced without holding the required lock or reference count, leading to a use‑after‑free. An attacker who can trigger the faulty path may cause unstable kernel behavior such as a crash, which could be exploited to crash the system or potentially privilege‑escalate if a kernel exploit can be chained. The description does not confirm a working exploit, but the UAF leaves the kernel in an undefined state when a concurrent close occurs.

Affected Systems

All Linux kernel releases that ship the unpatched Bluetooth SCO implementation are affected, regardless of distribution or custom kernel configuration. Any host running a kernel with Bluetooth enabled is potentially vulnerable, as the CNA product list indicates Linux:Linux with no version constraints.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score is reported as < 1%, suggesting that exploitation is unlikely at present. The use‑after‑free could lead to a kernel panic and is not listed in the CISA KEV catalog, and no public proof of exploitation exists. Since no public proof of exploitation exists, the threat is considered opportunistic and would require a malicious Bluetooth device to initiate a SCO connection that races with a concurrent socket close. Security professionals should treat the vulnerability as a potential denial‑of‑service and possible privilege‑escalation vector until further information becomes available.

Generated by OpenCVE AI on September 20, 2026 at 06:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the SCO use‑after‑free fix.
  • If updating the kernel is not immediately possible, disable the Bluetooth SCO subsystem or restrict its use to trusted devices via firewall rules or device trust policies.
  • Monitor system logs for kernel panic events or abnormal SIGKILL messages related to Bluetooth activity as an early indicator of exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8875-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8877-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8878-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8879-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8887-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8888-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8889-1 Linux kernel (OEM) vulnerabilities
History

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_sock_release sco_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) sco_sock_kill(sk) UAF on sk deref and similarly for access to sco_get_sock_listen() return value. Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.
Title Bluetooth: SCO: hold sk properly in sco_conn_ready
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:26.042Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:07.717

Modified: 2026-09-16T15:18:06.747

Link: CVE-2026-89774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses