Impact
The Linux kernel Bluetooth subsystem contains a flaw that can cause a pending Bluetooth Low Energy (LE) connection to leak from the internal BT_CONNECT state when a second connection attempt is rejected. The code incorrectly compares the pending connection with a lookup function that returns only the first connection, so a second failed connection is not cleaned up properly. This left‑over connection remains in BT_CONNECT indefinitely, causing subsequent LE connection attempts to fail with -EBUSY and preventing any further communication with all Bluetooth peers. The result is a persistent denial of service for any device using LTE connections until the adapter is reset.
Affected Systems
The vulnerability is present in the Linux kernel's Bluetooth stack; any Linux-based system that uses the kernel Bluetooth driver is potentially affected. The vendor list includes Linux:Linux and specific product information is not provided. Version information is missing from the data, so every kernel release prior to the patch that fixed this logic is susceptible.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. Because the bug is triggered by attempting a second LE connection while one is pending, an attacker would need the ability to send HCI commands to the local kernel—typically this requires local privilege or physical proximity to the device. The vulnerability offers no remote code execution; it provides a local denial-of-service condition that can disrupt Bluetooth functionality but cannot compromise system confidentiality or integrity.
OpenCVE Enrichment