{"id":"CVE-2026-89774","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: hold sk properly in sco_conn_ready\n\nsk deref in sco_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: hold sk properly in sco_conn_ready\n\nsk deref in sco_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. c…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < 50aae396dc30377bec8e3b181b8346f8fd38f7d8","Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < 6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1","Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < d141d9b769bcd1b747898528c5023270cda040f2","Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < 73cb063f5ec6ca51eb1e246c6d332563002ac277","Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < 7199c78c3a3e399a4dc439d845826793880ccedc","Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f < 4e37f6452d586b95c346a9abdd2fb80b67794f39","Linux 5.15"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:06.747","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89774","references":[{"url":"https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T08:52:29.589Z","epss":0.00318,"epssPercentile":0.24954,"slug":"CVE-2026-89774","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: hold sk properly in sco_conn_ready\n\nsk deref in sco_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. conn->sk and parent sk is\ncurrently accessed without either, and without checking parent->sk_state:\n\n    [Task 1]            [Task 2]\n                        sco_sock_release\n    sco_conn_ready\n      sk = conn->sk\n                          lock_sock(sk)\n                            conn->sk = NULL\n      lock_sock(sk)\n                          release_sock(sk)\n                          sco_sock_kill(sk)\n       UAF on sk deref\n\nand similarly for access to sco_get_sock_listen() return value.\n\nFix possible UAF by holding sk refcount in sco_conn_ready() and making\nsco_get_sock_listen() increase refcount. Also recheck after lock_sock\nthat the socket is still valid.  Adjust conn->sk locking so it's\nprotected also by lock_sock() of the associated socket if any.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205283,"id":"CVE-2026-89774","ts":1789570706102,"field":"cvss","old":null,"new":"8.8"},{"seq":205282,"id":"CVE-2026-89774","ts":1789570706102,"field":"severity","old":"none","new":"high"}]}