In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: fix refcounting of iso_conn
isoconndel() and isochandel() have a race that results to double-put of iso_conn:
[Task hdev->workqueue] [Task 2]
iso_conn_del iso_chan_del
iso_conn_hold_unless_zero iso_conn_lock
iso_conn_lock conn->sk = NULL
iso_conn_unlock
sk = iso_sock_hold(conn) <---------ยด
if (!sk) iso_conn_put iso_conn_put
iso_conn_put /* UAF */
The extra put for !sk in isoconndel() is currently required since failing isochanadd() may leave iso_conn not associated with any sk.
Fix by having isopi(sk)->conn own refcount when non-NULL, so isoconndel does not need to put it. Adjust the isoconn_add() refcounting so that conn is put if it does not get associated with an sk.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74534.json"
}