CVE-2026-89774
8.8 HIGHPublished 2026-09-16 · Updated 2026-09-16
AI risk analysis
- Summary
- This vulnerability allows for a use-after-free condition in the Linux kernel's Bluetooth SCO connection handling, which could lead to a denial of service or potentially other attacks if exploited.
- Exploitability
- Exploiting this vulnerability requires access to the Bluetooth stack and the ability to trigger a specific sequence of events. The attacker must have the capability to send crafted Bluetooth packets to the target system.
- Blast radius
- If exploited, the impact is limited to the local system, potentially leading to a denial of service or other kernel-level issues, but does not affect remote systems directly.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the fixed version 5.19.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_sock_release sco_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) sco_sock_kill(sk) UAF on sk deref and similarly for access to sco_get_sock_listen() return value. Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
All references
- https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39
- https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8
- https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
- https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc
- https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277
- https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-90256
- CRITICALCVE-2026-100075
- HIGHCVE-2026-64562
- CRITICALCVE-2026-64564
- HIGHCVE-2026-64575
- HIGHCVE-2026-64577
- HIGHCVE-2026-64580
- HIGHCVE-2026-64581
Related by shared AI tags and CWE weakness class. Browse the full archive.