PT-2026-94603 · Linux · Linux Kernel

CVE-2026-90255

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth component where hci setup sync() queues a conn handle t with a NULL destroy callback. This leads to a memory leak if the entry is cancelled, as hci cmd sync cancel entry() fails to release entry->data without a destroy callback, and hci cmd sync clear() cancels all pending entries during controller unregistration. Additionally, the context stores a bare hci conn pointer, allowing the connection to be freed while work is still queued because the dequeue process in hci conn del() does not correctly match the wrapper used in entry->data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102869
CVE-2026-90255
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel