Answer in brief
CVE-2026-74535 records a Unknown severity vulnerability in Bluetooth: ISO: avoid deadlocks in iso_sock_timeout. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a58d0f5dac322e16cc75334d000666512341bde5 <16d89a63e08280abeef7218970a3bbd7ca62b021 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <82e982f54f962f72646868ddbb2c3bd9ea178568 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <3c3d5f85db80145636bb991a6005e2760012b985 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43 || f53e7489273dc2bb307bf50f319b3762d45534f0 || >=6.12.2 <6.12.103 || >=6.11.11 <6.12 | 16d89a63e08280abeef7218970a3bbd7ca62b021, 82e982f54f962f72646868ddbb2c3bd9ea178568, 3c3d5f85db80145636bb991a6005e2760012b985, 200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43, 6.12.103, 6.12 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout iso_sock_timeout() takes lock_sock, so sync disabling the timer while holding that lock may deadlock. iso_sock_timeout() may also run concurrently with iso_conn_del(), which leads to UAF [Task 1] [Task hdev->workqueue] iso_sock_timeout iso_conn_del iso_conn_hold_unless_zero iso_chan_del `------------> iso_conn_put caller frees hcon iso_conn_put iso_conn_free conn->hcon->iso_data = NULL; /* UAF */ Fix the deadlock by removing the disable from the lock_sock sections. Move the timer from iso_conn to iso_pinfo to decouple it from iso_conn which may need to be freed in lock_sock section. Convert some of the clear_timer to disable_timer.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74535 records a Unknown severity vulnerability in Bluetooth: ISO: avoid deadlocks in iso_sock_timeout. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a58d0f5dac322e16cc75334d000666512341bde5 <16d89a63e08280abeef7218970a3bbd7ca62b021 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <82e982f54f962f72646868ddbb2c3bd9ea178568 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <3c3d5f85db80145636bb991a6005e2760012b985 || >=dc26097bdb864a0d5955b9a25e43376ffc1af99b <200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43 || f53e7489273dc2bb307bf50f319b3762d45534f0 || >=6.12.2 <6.12.103 || >=6.11.11 <6.12 | 16d89a63e08280abeef7218970a3bbd7ca62b021, 82e982f54f962f72646868ddbb2c3bd9ea178568, 3c3d5f85db80145636bb991a6005e2760012b985, 200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43, 6.12.103, 6.12 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout iso_sock_timeout() takes lock_sock, so sync disabling the timer while holding that lock may deadlock. iso_sock_timeout() may also run concurrently with iso_conn_del(), which leads to UAF [Task 1] [Task hdev->workqueue] iso_sock_timeout iso_conn_del iso_conn_hold_unless_zero iso_chan_del `------------> iso_conn_put caller frees hcon iso_conn_put iso_conn_free conn->hcon->iso_data = NULL; /* UAF */ Fix the deadlock by removing the disable from the lock_sock sections. Move the timer from iso_conn to iso_pinfo to decouple it from iso_conn which may need to be freed in lock_sock section. Convert some of the clear_timer to disable_timer.
Quoted source text, attributed separately from HOL analysis.