In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: serialize isosockclear_timer with socket lock
isosockclose() calls isosockcleartimer() before acquiring locksock(sk).
isosockcleartimer() reads isopi(sk)->conn twice without the socket lock held:
if (!iso_pi(sk)->conn)
return;
cancel_delayed_work(&iso_pi(sk)->conn->timeout_work);
Concurrently, isoconndel() executes under locksock(sk) and calls isochandel(), which sets isopi(sk)->conn to NULL and may result in the final reference to the connection being dropped:
CPU0 CPU1
---- ----
iso_sock_clear_timer()
if (conn != NULL) ... lock_sock(sk)
iso_chan_del()
iso_pi(sk)->conn = NULL
cancel_delayed_work(conn) /* NULL deref or UAF */
iso_pi(sk)->conn is not stable across the unlock window, causing a NULL pointer dereference or use-after-free.
Serialize isosockcleartimer() with the socket lock by moving it inside locksock()/releasesock(), matching the pattern used in isoconn_del() and all other call sites.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63945.json",
"cna_assigner": "Linux"
}