CVE-2026-63871: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
Published Jul 19, 2026
·Updated
Bluetooth: ISO: Fix data-race on isopi fields in hcigetroute calls
Affected Software
1 affected component
Linux Kernel Linux kernel
Event History
Jul 19, 2026
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
via NVD·03:16 PM
Description
Jul 20, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63871?
The severity of CVE-2026-63871 is rated at 12.
2
How do I fix CVE-2026-63871?
To fix CVE-2026-63871, update to the latest version of the Linux kernel where this vulnerability has been addressed.
3
What systems are affected by CVE-2026-63871?
CVE-2026-63871 affects the Bluetooth stack within the Linux kernel.
4
What types of calls are impacted by CVE-2026-63871?
CVE-2026-63871 affects calls to iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() that use hci_get_route().
5
What is the nature of the issue in CVE-2026-63871?
CVE-2026-63871 is related to a data-race condition on iso_pi fields in hci_get_route calls.