PatchSiren cyber security CVE debrief
CVE-2026-31408 Linux CVE debrief
CVE-2026-31408 is a high-severity Linux kernel memory-safety issue in Bluetooth SCO handling. The bug is a use-after-free in sco_recv_frame(): it reads conn->sk while holding sco_conn_lock(), but then releases the lock without first taking a socket reference. A concurrent close() can free the socket before the later sk->sk_state access. The fix is to hold the socket safely before unlocking and to drop the reference on all exit paths.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-08-19
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-08-19
Who should care
Linux kernel maintainers, distribution security teams, and operators of systems that use Bluetooth functionality—especially workloads where SCO traffic may be reachable in the running kernel.
Technical summary
NVD maps the issue to CWE-416 (Use After Free) and gives CVSS v3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerable code path is in Bluetooth SCO receive handling, where sco_recv_frame() accesses conn->sk under sco_conn_lock() but does not retain the socket object after unlocking. That creates a race with socket close/free. The supplied record also notes that nearby functions in the same file already use sco_sock_hold() correctly, and the fix is to adopt that pattern plus sock_put() on all exits. NVD’s affected version criteria cover multiple Linux kernel lines up to, but not including, the listed fixed releases.
Defensive priority
High. This is a kernel memory-safety flaw with potential impact on confidentiality, integrity, and availability, and NVD rates it 8.8/HIGH.
Recommended defensive actions
- Patch or upgrade to a kernel release that includes the fix; NVD lists fixed endpoints of 5.15.203, 6.1.168, 6.6.131, 6.12.80, 6.18.21, and 6.19.11 for the affected branches.
- If you maintain a downstream kernel, confirm the backport of the Bluetooth SCO socket-reference fix and the associated sock_put() cleanup.
- Prioritize systems that enable Bluetooth SCO handling or depend on Bluetooth kernel support, and verify vendor advisories for your exact kernel build.
- Use the official stable patch references from kernel.org to confirm whether your branch contains the correction.
- Track any fleet assets still on older kernel lines that fall within the NVD vulnerable ranges.
Evidence notes
The vulnerability description in the supplied CVE/NVD record states that sco_recv_frame() releases sco_conn_lock() before holding a reference to conn->sk, allowing concurrent close() to free the socket and causing a use-after-free. NVD classifies the weakness as CWE-416 and assigns CVSS v3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The record also includes official kernel.org stable patch references, which corroborate that this is a patched kernel issue rather than an unverified report.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31408 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31408
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31408 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31408
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/108b81514d8f2535eb16651495cefb2250528db3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/45aaca995e4a7a05b272a58e7ab2fff4f611b8f1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/598dbba9919c5e36c54fe1709b557d64120cb94b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b0a7da0e3f7442545f071499beb36374714bb9de
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d57384e27d1ebf0047e3f00a6e1181b8be9857a2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e76e8f0581ef555eacc11dbb095e602fb30a5361
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.