Bluetooth Vulnerability in Linux Kernel by The Linux Foundation
CVE-2026-74539
What is CVE-2026-74539?
A vulnerability has been identified in the Linux kernel affecting Bluetooth functionality. Specifically, the issue arises in the iso_sock_getname function, where the iso_pi(socket)->conn requires the lock_sock to be held but is not. This oversight could lead to potential access issues or exploitation risks, as the lack of proper locking mechanisms may allow unauthorized access to the connection information. The vulnerability has been addressed by implementing necessary lock and release commands to ensure secure access and maintain system integrity.
Affected Version(s)
Linux 2df108c227b266a9ec9e3fda3828d2ac9662aa33 < 72d5bb1d77d7c3330146dc0cfd43f704c64b9594
Linux 2df108c227b266a9ec9e3fda3828d2ac9662aa33 < 202670e6602e068558c1fca2df40719ee91a2906
Linux 2df108c227b266a9ec9e3fda3828d2ac9662aa33 < 89cf154d7c18e6e94a3da83051f3cf2bac317ae2