CVE-2026-89774

Source
https://cve.org/CVERecord?id=CVE-2026-89774
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89774.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89774
Downstream
Published
2026-09-16T08:24:21Z
Modified
2026-09-17T03:47:22Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: SCO: hold sk properly in sco_conn_ready
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state:

[Task 1]            [Task 2]
                    sco_sock_release
sco_conn_ready
  sk = conn->sk
                      lock_sock(sk)
                        conn->sk = NULL
  lock_sock(sk)
                      release_sock(sk)
                      sco_sock_kill(sk)
   UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89774.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
27c24fda62b601d6f9ca5e992502578c4310876f
Fixed
50aae396dc30377bec8e3b181b8346f8fd38f7d8
Fixed
6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
Fixed
d141d9b769bcd1b747898528c5023270cda040f2
Fixed
73cb063f5ec6ca51eb1e246c6d332563002ac277
Fixed
7199c78c3a3e399a4dc439d845826793880ccedc
Fixed
4e37f6452d586b95c346a9abdd2fb80b67794f39

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89774.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89774.json"