Impact
The vulnerability arises from the kernel's Bluetooth hci_sync module failing to free a kmalloc‑allocated advertising instance on failure and cancellation paths. This omission results in a memory leak, a classic case of Resources Not Being Released (CWE‑401). In the kernel context, sustained memory leaks can deplete system memory, causing process thrashing or kernel crashes, effectively interrupting normal operation and presenting a denial‑of‑service surface.
Affected Systems
All Linux kernel versions that contain the buggy Bluetooth hci_sync implementation are affected, regardless of distribution. The specific flaw has been patched in subsequent kernel releases, but until a distribution applies that update, any Linux host running the identified code path remains vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of analysis. This vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered by sending crafted Bluetooth advertising packets or by the system attempting to queue advertising commands that fail or are cancelled. Attackers with remote Bluetooth access could potentially cause repeated allocation of advertising instances that are never released, leading to cumulative memory pressure. Because the flaw is in kernel code, local escalation to root is not required to exploit, but a privileged user or an exploit that can command Bluetooth traffic may reset the kernel’s memory allocator and produce a denial‑of‑service. The impact would be limited to the affected host, not to other hosts on the network.
OpenCVE Enrichment
Debian DLA
Debian DSA