๐Ÿ” CVE Alert

CVE-2026-90255

UNKNOWN 0.0

Bluetooth: hci_conn: fix the SCO setup context lifetime

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context lifetime hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so the context is only freed if hci_enhanced_setup_sync() actually runs. An entry that is cancelled instead is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. The context also stores a bare hci_conn pointer, so the connection can be freed while the work is queued. The dequeue in hci_conn_del() does not cover it either, as it matches on entry->data == conn and entry->data is the wrapper here. Same problem as commit 2f5d635ad590 ("Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks"). Hold the connection and release both from a destroy callback. The submission failure path drops both, since hci_cmd_sync_submit() does not call the destroy callback when it fails to queue.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < 37cfec41365c826d5496ef5d00c9e215eee53aa2 e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < 9a2ba69cebe3fc5a3d4fa8eaaad3c42862723c27 e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < a661de0ee29d0915c5e924edf91d2be2b4d35bae e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < c1fe3c74a89a7749cba3caa0dd91236049c66116 e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < 4d7b1c834d2775b73c65e4888e01f5af8b477fe9 e07a06b4eb417f5271d33ce2240e93c62d98b7b4 < 42de40abe25db9211107af8896d0fd741f10648d
Linux / Linux
6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/37cfec41365c826d5496ef5d00c9e215eee53aa2 git.kernel.org: https://git.kernel.org/stable/c/9a2ba69cebe3fc5a3d4fa8eaaad3c42862723c27 git.kernel.org: https://git.kernel.org/stable/c/a661de0ee29d0915c5e924edf91d2be2b4d35bae git.kernel.org: https://git.kernel.org/stable/c/c1fe3c74a89a7749cba3caa0dd91236049c66116 git.kernel.org: https://git.kernel.org/stable/c/4d7b1c834d2775b73c65e4888e01f5af8b477fe9 git.kernel.org: https://git.kernel.org/stable/c/42de40abe25db9211107af8896d0fd741f10648d