CVE-2026-98293
Received Received - Intake

Bluetooth Socket Leak in Linux Kernel

Vulnerability report for CVE-2026-98293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() iso_get_sock() returns the parent socket with a reference held, which is dropped by sock_put() once the child socket has been set up. The error path taken when iso_sock_alloc() fails only calls release_sock() and returns, leaking the reference and thus the parent socket itself. Drop the reference on that path as well.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux 11dc486ed5d4626e6b92a23b67ed76cb6c48bfc9
Linux Linux fa224d0c094a458e9ebf5ea9b1c696136b7af427
Linux Linux fa224d0c094a458e9ebf5ea9b1c696136b7af427
Linux Linux fa224d0c094a458e9ebf5ea9b1c696136b7af427
Linux Linux fa224d0c094a458e9ebf5ea9b1c696136b7af427
Linux Linux 6.6.67
Linux Linux 6.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Bluetooth ISO (isochronous) socket vulnerability in the Linux kernel. It involves a reference leak in the parent socket during child socket setup. When iso_sock_alloc() fails, the error path does not properly release the parent socket reference obtained via iso_get_sock(), causing a memory leak.

Detection Guidance

This vulnerability is specific to the Linux kernel's Bluetooth ISO implementation and does not have direct network detection commands. Detection requires checking kernel versions and Bluetooth stack configurations. Review kernel logs for Bluetooth-related errors or crashes using 'dmesg | grep -i bluetooth' or 'journalctl -k | grep -i bluetooth'.

Impact Analysis

This vulnerability could lead to resource exhaustion in the Linux kernel due to unreleased socket references. This may cause system instability, crashes, or degraded performance, particularly in systems using Bluetooth ISO sockets.

Mitigation Strategies

Apply the latest Linux kernel updates to patch this vulnerability. Reboot the system after updating to ensure the patched kernel is active. Disable Bluetooth if not in use via 'rfkill block bluetooth' as a temporary measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart