PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31408 Linux CVE debrief

CVE-2026-31408 is a high-severity Linux kernel memory-safety issue in Bluetooth SCO handling. The bug is a use-after-free in sco_recv_frame(): it reads conn->sk while holding sco_conn_lock(), but then releases the lock without first taking a socket reference. A concurrent close() can free the socket before the later sk->sk_state access. The fix is to hold the socket safely before unlocking and to drop the reference on all exit paths.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-08-19
Advisory published
2026-04-06
Advisory updated
2026-08-19

Who should care

Linux kernel maintainers, distribution security teams, and operators of systems that use Bluetooth functionality—especially workloads where SCO traffic may be reachable in the running kernel.

Technical summary

NVD maps the issue to CWE-416 (Use After Free) and gives CVSS v3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerable code path is in Bluetooth SCO receive handling, where sco_recv_frame() accesses conn->sk under sco_conn_lock() but does not retain the socket object after unlocking. That creates a race with socket close/free. The supplied record also notes that nearby functions in the same file already use sco_sock_hold() correctly, and the fix is to adopt that pattern plus sock_put() on all exits. NVD’s affected version criteria cover multiple Linux kernel lines up to, but not including, the listed fixed releases.

Defensive priority

High. This is a kernel memory-safety flaw with potential impact on confidentiality, integrity, and availability, and NVD rates it 8.8/HIGH.

Recommended defensive actions

  • Patch or upgrade to a kernel release that includes the fix; NVD lists fixed endpoints of 5.15.203, 6.1.168, 6.6.131, 6.12.80, 6.18.21, and 6.19.11 for the affected branches.
  • If you maintain a downstream kernel, confirm the backport of the Bluetooth SCO socket-reference fix and the associated sock_put() cleanup.
  • Prioritize systems that enable Bluetooth SCO handling or depend on Bluetooth kernel support, and verify vendor advisories for your exact kernel build.
  • Use the official stable patch references from kernel.org to confirm whether your branch contains the correction.
  • Track any fleet assets still on older kernel lines that fall within the NVD vulnerable ranges.

Evidence notes

The vulnerability description in the supplied CVE/NVD record states that sco_recv_frame() releases sco_conn_lock() before holding a reference to conn->sk, allowing concurrent close() to free the socket and causing a use-after-free. NVD classifies the weakness as CWE-416 and assigns CVSS v3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The record also includes official kernel.org stable patch references, which corroborate that this is a patched kernel issue rather than an unverified report.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31408 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31408

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31408 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31408

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/108b81514d8f2535eb16651495cefb2250528db3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/45aaca995e4a7a05b272a58e7ab2fff4f611b8f1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/598dbba9919c5e36c54fe1709b557d64120cb94b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b0a7da0e3f7442545f071499beb36374714bb9de

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d57384e27d1ebf0047e3f00a6e1181b8be9857a2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e76e8f0581ef555eacc11dbb095e602fb30a5361

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.