In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: hold sk properly in isoconnready
sk deref in isoconnready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk is currently accessed without either:
[Task 1] [Task 2]
iso_sock_release
iso_conn_ready
sk = conn->sk
lock_sock(sk)
conn->sk = NULL
lock_sock(sk)
release_sock(sk)
iso_sock_kill(sk)
UAF on sk deref
Fix possible UAF by holding sk refcount in isoconnready(). Also recheck after locksock that the socket is still valid. Adjust locking so conn->sk is cleared only under locksock.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74537.json"
}