PT-2026-52347 · Linux+1 · Linux Kernel+1

CVE-2026-53252

·

Published

2026-06-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak occurs in the Bluetooth HCI UART configuration during early failures in the hci alloc dev() function. When device initialization fails before hci register dev() completes, the HCI UNREGISTER flag is not set. Consequently, when the device reference count reaches zero, the bt host release() function performs a direct kfree(hdev) instead of calling hci release dev(). This bypasses the cleanup of the SRCU (Sleep-Read-Copy-Update) struct, which is a synchronization mechanism used in the kernel, leading to a leak of percpu memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90494
CVE-2026-53252
ECHO-88C0-5306-731F
OESA-2026-2930
OESA-2026-3204
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3594-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu