PT-2026-94435 · Linux · Linux Kernel
CVE-2026-90087
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Bluetooth subsystem where an
hci conn is leaked when a second Low Energy (LE) connection attempt is rejected. This occurs because the create le conn complete() function incorrectly determines if a failed connection is still pending by comparing it against the result of hci lookup le connect(), which only returns the first LE connection in the BT CONNECT state. When two connections are pending simultaneously, the lookup may return the wrong connection, causing the system to drop the error and skip the hci conn failed() function for the connection that actually failed.As a result, the leaked connection remains in the
BT CONNECT state indefinitely. Since hci connect le() prevents new dialing attempts while any connection is found by hci lookup le connect(), all subsequent attempts to connect to any peer fail with an -EBUSY error, and no commands reach the controller until the adapter is reset.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel