---
id: CVE-2026-89774
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: SCO: hold sk properly in sco_conn_ready

  sk deref in sco_conn_ready must be done either under conn->lock, or
  holding a refcount, to avoid concurrent close
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: SCO: hold sk properly in sco_conn_ready

  sk deref in sco_conn_ready must be done either under conn->lock, or
  holding a refcount, to avoid concurrent close. c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    50aae396dc30377bec8e3b181b8346f8fd38f7d8
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    d141d9b769bcd1b747898528c5023270cda040f2
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    73cb063f5ec6ca51eb1e246c6d332563002ac277
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    7199c78c3a3e399a4dc439d845826793880ccedc
  - >-
    Linux >= 27c24fda62b601d6f9ca5e992502578c4310876f <
    4e37f6452d586b95c346a9abdd2fb80b67794f39
  - Linux 5.15
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:06.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89774'
references:
  - url: 'https://git.kernel.org/stable/c/4e37f6452d586b95c346a9abdd2fb80b67794f39'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/50aae396dc30377bec8e3b181b8346f8fd38f7d8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6e3840578aaad1a296aab1eaaa89ea3b7d5cbae1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7199c78c3a3e399a4dc439d845826793880ccedc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/73cb063f5ec6ca51eb1e246c6d332563002ac277'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d141d9b769bcd1b747898528c5023270cda040f2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T08:52:29.589Z'
epss: 0.00403
epssPercentile: 0.31694
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk and parent sk is
currently accessed without either, and without checking parent->sk_state:

    [Task 1]            [Task 2]
                        sco_sock_release
    sco_conn_ready
      sk = conn->sk
                          lock_sock(sk)
                            conn->sk = NULL
      lock_sock(sk)
                          release_sock(sk)
                          sco_sock_kill(sk)
       UAF on sk deref

and similarly for access to sco_get_sock_listen() return value.

Fix possible UAF by holding sk refcount in sco_conn_ready() and making
sco_get_sock_listen() increase refcount. Also recheck after lock_sock
that the socket is still valid.  Adjust conn->sk locking so it's
protected also by lock_sock() of the associated socket if any.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
