PT-2026-94603 · Linux · Linux Kernel
CVE-2026-90255
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Bluetooth component where
hci setup sync() queues a conn handle t with a NULL destroy callback. This leads to a memory leak if the entry is cancelled, as hci cmd sync cancel entry() fails to release entry->data without a destroy callback, and hci cmd sync clear() cancels all pending entries during controller unregistration. Additionally, the context stores a bare hci conn pointer, allowing the connection to be freed while work is still queued because the dequeue process in hci conn del() does not correctly match the wrapper used in entry->data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel