Impact
The vulnerability arises in the Linux kernel's Bluetooth interface when the function responsible for terminating ISO big user connections fails to free allocated memory in a specific early‑return path. The allocated structure is not deallocated when neither the PA nor BIG sync termination flags are set, causing a memory leak. A continuous or repeated abuse of this behavior could deplete kernel memory, potentially resulting in a denial of service for processes relying on kernel resources.
Affected Systems
Linux kernel builds that include the unpatched Bluetooth implementation, covering all vendors that ship a stock kernel with the Bluetooth subsystem compiled in. No specific kernel version range is listed; any kernel prior to the inclusion of the patch is considered affected.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low exploitation probability. Because the flaw resides in kernel space and requires interaction with the Bluetooth stack, it is inferred that the attack vector is local, possibly through a crafted Bluetooth connection or an untrusted device attempting to trigger repeated termination calls. While no public exploits are reported, the potential for resource depletion makes it a high‑value local threat.
OpenCVE Enrichment
Ubuntu USN