PT-2026-94435 · Linux · Linux Kernel

CVE-2026-90087

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth subsystem where an hci conn is leaked when a second Low Energy (LE) connection attempt is rejected. This occurs because the create le conn complete() function incorrectly determines if a failed connection is still pending by comparing it against the result of hci lookup le connect(), which only returns the first LE connection in the BT CONNECT state. When two connections are pending simultaneously, the lookup may return the wrong connection, causing the system to drop the error and skip the hci conn failed() function for the connection that actually failed.
As a result, the leaked connection remains in the BT CONNECT state indefinitely. Since hci connect le() prevents new dialing attempts while any connection is found by hci lookup le connect(), all subsequent attempts to connect to any peer fail with an -EBUSY error, and no commands reach the controller until the adapter is reset.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102389
CVE-2026-90087
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel