CVE-2026-31408
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/04/2026
Última modificación:
07/04/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold<br />
<br />
sco_recv_frame() reads conn->sk under sco_conn_lock() but immediately<br />
releases the lock without holding a reference to the socket. A concurrent<br />
close() can free the socket between the lock release and the subsequent<br />
sk->sk_state access, resulting in a use-after-free.<br />
<br />
Other functions in the same file (sco_sock_timeout(), sco_conn_del())<br />
correctly use sco_sock_hold() to safely hold a reference under the lock.<br />
<br />
Fix by using sco_sock_hold() to take a reference before releasing the<br />
lock, and adding sock_put() on all exit paths.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/108b81514d8f2535eb16651495cefb2250528db3
- https://git.kernel.org/stable/c/45aaca995e4a7a05b272a58e7ab2fff4f611b8f1
- https://git.kernel.org/stable/c/598dbba9919c5e36c54fe1709b557d64120cb94b
- https://git.kernel.org/stable/c/7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e
- https://git.kernel.org/stable/c/e76e8f0581ef555eacc11dbb095e602fb30a5361



