Sploitus

CVE-2026-74535

No indexed exploits for CVE-2026-74535 yet

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout iso_sock_timeout() takes lock_sock, so sync disabling the timer while holding that lock may deadlock. iso_sock_timeout() may also run concurrently with iso_conn_del(), which leads to UAF [Task 1] [Task hdev->workqueue] iso_sock_timeout iso_conn_del iso_conn_hold_unless_zero iso_chan_del `------------> iso_conn_put caller frees hcon iso_conn_put iso_conn_free conn->hcon->iso_data = NULL; /* UAF */ Fix the deadlock by removing the disable from the lock_sock sections. Move the timer from iso_conn to iso_pinfo to decouple it from iso_conn which may need to be freed in lock_sock section. Convert some of the clear_timer to disable_timer.

CVSS 3.1
8.8 HIGH
EPSS
0.2% (15th percentile)
NVD status
Received
Published
2026-08-15
CVE-2026-74535 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-74535 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-74535 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.