CVE-2026-98293

high

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() iso_get_sock() returns the parent socket with a reference held, which is dropped by sock_put() once the child socket has been set up. The error path taken when iso_sock_alloc() fails only calls release_sock() and returns, leaking the reference and thus the parent socket itself. Drop the reference on that path as well.

References

https://git.kernel.org/stable/c/f016daabd4fec4e9b8563f8b6f42eabce0ca66b0

https://git.kernel.org/stable/c/ea8a262662be62c095789924c11722ecbf40a4de

https://git.kernel.org/stable/c/e2b156a8d25966be49c1f809b654a2c4bb16564d

https://git.kernel.org/stable/c/ca18ee413a7cb6f09885778039225e58bae0d607

https://git.kernel.org/stable/c/9228f87365e68a6cae191f57f456e89a6d2167cf

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93221

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00175