KernelScan.io

HIGH

bluetooth IsoData UAF

CVE-2026-74541

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data always when detaching conn from hcon When setting conn->hcon = NULL, also conn->hcon->iso_data = NULL is necessary, otherwise later iso_conn_free() will UAF. Fix clearing of iso_data in iso_sock_disconn() Fixes KASAN: slab-use-after-free in iso_conn_hold_unless_zero on iso_sock_release() followed by hci_abort_conn_sync().

02

Engine v0.6.0

Risk summary

A local user with access to Bluetooth sockets can trigger a use-after-free in the ISO subsystem by racing socket release against connection abort. The dangling pointer left in the HCI connection's iso_data field allows heap corruption, potentially leading to privilege escalation, information disclosure, or kernel panic. Bluetooth hardware must be present and enabled for the vulnerable code path to be reachable.

Affectednet/bluetooth/iso.c (Bluetooth ISO)

Vulnerability analysis

When an ISO socket is disconnected, the code detaches the ISO connection from the underlying HCI connection by nulling the forward pointer but neglects to clear the back-pointer stored in the HCI connection. That stale pointer is later dereferenced during connection abort handling, accessing freed memory. The fix clears the back-pointer before detaching, ensuring neither side holds a dangling reference. The race is triggered by a local user closing an ISO socket while the connection is being aborted, so an attacker needs local access to a machine with Bluetooth enabled and an active ISO connection.

03

BranchIntroducedFixed inPatch commit
6.56.5.126.6cc1d39946d62
6.6—6.6.1517b51a9c25e96
6.12—6.12.10363c0f396a18b
6.18—6.18.4469a4a7b162b3
mainline—7.2-rc6—
7.1—7.1.8d57e506f6a1e