GHSA-g3p6-8r9x-w9g7HighCVSS 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state:

[Task 1]            [Task 2]
                    sco_sock_release
sco_conn_ready
  sk = conn->sk
                      lock_sock(sk)
                        conn->sk = NULL
  lock_sock(sk)
                      release_sock(sk)
                      sco_sock_kill(sk)
   UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.

🔗 References (8)