CVE-2026-63945

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock<br /> <br /> iso_sock_close() calls iso_sock_clear_timer() before acquiring<br /> lock_sock(sk).<br /> <br /> iso_sock_clear_timer() reads iso_pi(sk)-&gt;conn twice without the<br /> socket lock held:<br /> <br /> if (!iso_pi(sk)-&gt;conn)<br /> return;<br /> cancel_delayed_work(&amp;iso_pi(sk)-&gt;conn-&gt;timeout_work);<br /> <br /> Concurrently, iso_conn_del() executes under lock_sock(sk) and calls<br /> iso_chan_del(), which sets iso_pi(sk)-&gt;conn to NULL and may result in<br /> the final reference to the connection being dropped:<br /> <br /> CPU0 CPU1<br /> ---- ----<br /> iso_sock_clear_timer()<br /> if (conn != NULL) ... lock_sock(sk)<br /> iso_chan_del()<br /> iso_pi(sk)-&gt;conn = NULL<br /> cancel_delayed_work(conn) /* NULL deref or UAF */<br /> <br /> iso_pi(sk)-&gt;conn is not stable across the unlock window, causing a<br /> NULL pointer dereference or use-after-free.<br /> <br /> Serialize iso_sock_clear_timer() with the socket lock by moving it<br /> inside lock_sock()/release_sock(), matching the pattern used in<br /> iso_conn_del() and all other call sites.