CVE-2026-80721: Linux

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not dereference the hcon any more. Currently, clearing iso_conn::hcon relies on iso_conn_del() releasing the last reference to the iso_conn. Simplify this by explicitly clearing conn->hcon in iso_conn_del(), to avoid more complex reasoning on races about who holds the last reference.

Affected products

  • Linux Linux: from 6.11.11, before 6.12 (fixed in 6.12); from 6.12.2, before 6.13 (fixed in 6.13); from 6.13, before 6.18.44 (fixed in 6.18.44); from 6.19, before 7.1.8 (fixed in 7.1.8)

Published 2026-08-28. Last modified 2026-08-30.