CVE-2026-74538 evidence review
Linux
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_connect_ind Accessing iso_pi(sk)->conn requires lock_sock, which is not taken in the "ev3" part of iso_connect_ind. It may also be NULL if socket has transitioned away from the LISTEN/CONNECT states before locking. Fix by adding lock/release. Recheck hcon is valid after lock acquire where needed.
This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.
Identify the product and installed version
Record whether Linux is present, where it is installed, and which interfaces are exposed.
- Record the product name, package or appliance identifier, and installed version.
- Identify internet-facing, administrative, API, and internal access paths.
- Preserve the pre-change configuration and relevant service logs.
Compare the affected range
Use the current record as an identification aid: >= 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb < e8e9cff6d80eeec28dec4cf7cc18662986945391, >= 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb < 9bee7e476534f27e830658dad962d85da9edf6bf, >= 168d9bf9c7f01df71e6404cfff66d9c2a8e968fb < 4311fd6f429065a8ba208660360a895627a00cf3, >= 489efc9ae36f164423f5fa7ace772a7ab8131cd8, >= 6.8.9 < 6.9, >= 6.9. Resolve incomplete inventory results before deciding that an asset is unaffected.
Verify the authoritative remediation source
Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.
Operational boundary
This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.