← Back to search

CVE-2026-89774

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
This vulnerability allows for a use-after-free condition in the Linux kernel's Bluetooth SCO connection handling, which could lead to a denial of service or potentially other attacks if exploited.
Exploitability
Exploiting this vulnerability requires access to the Bluetooth stack and the ability to trigger a specific sequence of events. The attacker must have the capability to send crafted Bluetooth packets to the target system.
Blast radius
If exploited, the impact is limited to the local system, potentially leading to a denial of service or other kernel-level issues, but does not affect remote systems directly.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 5.19.1 or later.
dosbluetoothkernel

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_sock_release sco_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) sco_sock_kill(sk) UAF on sk deref and similarly for access to sco_get_sock_listen() return value. Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.