Linux Kernel Bluetooth Vulnerability in SCO Socket Reference Management
CVE-2026-80683

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80683?

A vulnerability in the Linux Kernel's Bluetooth SCO (Synchronous Connection-Oriented) sockets was identified, arising from improper reference management for socket connections. The issue occurs when a socket does not maintain its own reference while borrowing the connection reference from the caller. This can lead to use-after-free scenarios, where the socket's reference is released prematurely, potentially causing system instability or crashes. The vulnerability has been addressed by ensuring each socket owns its own connection reference, preventing scenarios where a connection is freed while still in use, thereby bolstering the stability of Bluetooth operations within the Linux Kernel.

Affected Version(s)

Linux e6720779ae612a14ac4ba7fe4fd5b27d900d932c

Linux e6720779ae612a14ac4ba7fe4fd5b27d900d932c < 8fe627192fa5da7157f9a48608f13c04b6373e43

Linux e6720779ae612a14ac4ba7fe4fd5b27d900d932c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.