Answer in brief
CVE-2026-74534 records a Unknown severity vulnerability in Bluetooth: ISO: fix refcounting of iso_conn. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <3b921533e8aa95b77aadcf31737595578e735f3c || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <8208b4939afb0a1977fffe902c3ca42fe0f3baaa || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <fdfde532ab1caa165fcd8985001157ac8b4db365 || f53e7489273dc2bb307bf50f319b3762d45534f0 || a58d0f5dac322e16cc75334d000666512341bde5 || >=6.11.11 <6.12 || >=6.12.2 <6.13 | 3b921533e8aa95b77aadcf31737595578e735f3c, 8208b4939afb0a1977fffe902c3ca42fe0f3baaa, fdfde532ab1caa165fcd8985001157ac8b4db365, 6.12, 6.13 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn iso_conn_del() and iso_chan_del() have a race that results to double-put of iso_conn: [Task hdev->workqueue] [Task 2] iso_conn_del iso_chan_del iso_conn_hold_unless_zero iso_conn_lock iso_conn_lock conn->sk = NULL iso_conn_unlock sk = iso_sock_hold(conn) <---------´ if (!sk) iso_conn_put iso_conn_put iso_conn_put /* UAF */ The extra put for !sk in iso_conn_del() is currently required since failing iso_chan_add() may leave iso_conn not associated with any sk. Fix by having iso_pi(sk)->conn own refcount when non-NULL, so iso_conn_del does not need to put it. Adjust the iso_conn_add() refcounting so that conn is put if it does not get associated with an sk.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74534 records a Unknown severity vulnerability in Bluetooth: ISO: fix refcounting of iso_conn. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <3b921533e8aa95b77aadcf31737595578e735f3c || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <8208b4939afb0a1977fffe902c3ca42fe0f3baaa || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <fdfde532ab1caa165fcd8985001157ac8b4db365 || f53e7489273dc2bb307bf50f319b3762d45534f0 || a58d0f5dac322e16cc75334d000666512341bde5 || >=6.11.11 <6.12 || >=6.12.2 <6.13 | 3b921533e8aa95b77aadcf31737595578e735f3c, 8208b4939afb0a1977fffe902c3ca42fe0f3baaa, fdfde532ab1caa165fcd8985001157ac8b4db365, 6.12, 6.13 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn iso_conn_del() and iso_chan_del() have a race that results to double-put of iso_conn: [Task hdev->workqueue] [Task 2] iso_conn_del iso_chan_del iso_conn_hold_unless_zero iso_conn_lock iso_conn_lock conn->sk = NULL iso_conn_unlock sk = iso_sock_hold(conn) <---------´ if (!sk) iso_conn_put iso_conn_put iso_conn_put /* UAF */ The extra put for !sk in iso_conn_del() is currently required since failing iso_chan_add() may leave iso_conn not associated with any sk. Fix by having iso_pi(sk)->conn own refcount when non-NULL, so iso_conn_del does not need to put it. Adjust the iso_conn_add() refcounting so that conn is put if it does not get associated with an sk.
Quoted source text, attributed separately from HOL analysis.