Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths

adv_timeout_expire() hands a kmalloc()ed instance byte to
hci_cmd_sync_queue() with a NULL destroy callback, and only
adv_timeout_expire_sync() frees it. That leaks on two paths:

- the return value is not checked, and hci_cmd_sync_queue() does not
take ownership when it fails (-ENETDOWN, -ENODEV, -ENOMEM);

- a cancelled entry is not released, as _hci_cmd_sync_cancel_entry()
does not free entry->data when there is no destroy callback.
hci_cmd_sync_clear() cancels every pending entry when the controller
is unregistered.

Free the buffer from a destroy callback, and in the caller when the entry
could not be queued at all.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory leak leading to potential denial of service in the Linux kernel's Bluetooth subsystem
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from the kernel's Bluetooth hci_sync module failing to free a kmalloc‑allocated advertising instance on failure and cancellation paths. This omission results in a memory leak, a classic case of Resources Not Being Released (CWE‑401). In the kernel context, sustained memory leaks can deplete system memory, causing process thrashing or kernel crashes, effectively interrupting normal operation and presenting a denial‑of‑service surface.

Affected Systems

All Linux kernel versions that contain the buggy Bluetooth hci_sync implementation are affected, regardless of distribution. The specific flaw has been patched in subsequent kernel releases, but until a distribution applies that update, any Linux host running the identified code path remains vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of analysis. This vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered by sending crafted Bluetooth advertising packets or by the system attempting to queue advertising commands that fail or are cancelled. Attackers with remote Bluetooth access could potentially cause repeated allocation of advertising instances that are never released, leading to cumulative memory pressure. Because the flaw is in kernel code, local escalation to root is not required to exploit, but a privileged user or an exploit that can command Bluetooth traffic may reset the kernel’s memory allocator and produce a denial‑of‑service. The impact would be limited to the affected host, not to other hosts on the network.

Generated by OpenCVE AI on September 19, 2026 at 03:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the fix for CVE‑2026‑90254.
  • If an immediate kernel update is unavailable, disable or uninstall the Bluetooth subsystem or the hci_sync driver until the patch is released.
  • Monitor system memory usage for abnormal growth and reboot the host if memory consumption approaches critical levels.
  • Apply the upstream patch from commit 120d8dc042e3d45073bb6e50ee7b058a0b182627 or equivalent to a custom kernel build if you maintain a local kernel source.

Generated by OpenCVE AI on September 19, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths adv_timeout_expire() hands a kmalloc()ed instance byte to hci_cmd_sync_queue() with a NULL destroy callback, and only adv_timeout_expire_sync() frees it. That leaks on two paths: - the return value is not checked, and hci_cmd_sync_queue() does not take ownership when it fails (-ENETDOWN, -ENODEV, -ENOMEM); - a cancelled entry is not released, as _hci_cmd_sync_cancel_entry() does not free entry->data when there is no destroy callback. hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Free the buffer from a destroy callback, and in the caller when the entry could not be queued at all.
Title Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:54.123Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.730

Modified: 2026-09-17T17:17:21.730

Link: CVE-2026-90254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:15:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime