CVE-2026-89774
8.8Linux · Kernel
A Use-After-Free vulnerability in the Linux kernel Bluetooth SCO implementation allows potential local or adjacent attackers to trigger memory corruption and system instability.
Executive summary
A high-severity Use-After-Free vulnerability in the Linux kernel Bluetooth subsystem poses a significant risk of system crashes or potential code execution for attackers within radio range.
Vulnerability
This flaw exists in the Bluetooth Synchronous Connection-Oriented (SCO) link handling, where improper reference counting during connection setup leads to a Use-After-Free condition. The vulnerability is exploitable by unauthenticated attackers in the immediate vicinity of the target device.
Business impact
Successful exploitation of this vulnerability can lead to kernel-level memory corruption, resulting in immediate system crashes (Denial of Service) or potential arbitrary code execution. Given the CVSS score of 8.8, this represents a critical risk to infrastructure stability and data integrity, particularly for systems where Bluetooth is enabled and exposed to untrusted environments.
Remediation
Immediate Action: Update your Linux kernel to the versions provided by your distribution vendor, specifically ensuring a minimum of 5.15.212, 6.1.178, 6.6.145, or 6.12.97.
Proactive Monitoring: Monitor system logs for kernel panic events or unexpected crashes related to the Bluetooth subsystem (hci_core or sco modules).
Compensating Controls: If patching is not immediately feasible, disable Bluetooth services on vulnerable systems to eliminate the attack vector.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a high risk due to its location within the kernel and the potential for unauthenticated exploitation over Bluetooth. Administrators should prioritize the deployment of kernel updates across all affected hardware, particularly for mobile or IoT devices where Bluetooth remains active. Apply the specified patched versions as soon as they are available in your distribution repository.
More Linux CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section