Bluetooth Vulnerability in Linux Kernel Affects Multiple Devices
CVE-2026-74538
Currently unrated
What is CVE-2026-74538?
A vulnerability exists in the Linux kernel within the Bluetooth module, specifically during the iso_connect_ind function where the socket is accessed without proper locking. This issue can lead to potential misuse of resources, especially if the socket state has transitioned away before the lock is acquired. A fix has been implemented to address this by ensuring that locks are properly added and released during the connection indication process, thereby enhancing the stability and security of Bluetooth operations.
Affected Version(s)
Linux 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb
Linux 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb < 9bee7e476534f27e830658dad962d85da9edf6bf
Linux 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb < 4311fd6f429065a8ba208660360a895627a00cf3