CVE-2026-31408
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/04/2026
Last modified:
06/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold<br />
<br />
sco_recv_frame() reads conn->sk under sco_conn_lock() but immediately<br />
releases the lock without holding a reference to the socket. A concurrent<br />
close() can free the socket between the lock release and the subsequent<br />
sk->sk_state access, resulting in a use-after-free.<br />
<br />
Other functions in the same file (sco_sock_timeout(), sco_conn_del())<br />
correctly use sco_sock_hold() to safely hold a reference under the lock.<br />
<br />
Fix by using sco_sock_hold() to take a reference before releasing the<br />
lock, and adding sock_put() on all exit paths.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/108b81514d8f2535eb16651495cefb2250528db3
- https://git.kernel.org/stable/c/45aaca995e4a7a05b272a58e7ab2fff4f611b8f1
- https://git.kernel.org/stable/c/598dbba9919c5e36c54fe1709b557d64120cb94b
- https://git.kernel.org/stable/c/7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e
- https://git.kernel.org/stable/c/e76e8f0581ef555eacc11dbb095e602fb30a5361



