Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_conn: fix the SCO setup context lifetime

hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so
the context is only freed if hci_enhanced_setup_sync() actually runs. An
entry that is cancelled instead is leaked, as
_hci_cmd_sync_cancel_entry() does not release entry->data when there is
no destroy callback, and hci_cmd_sync_clear() cancels every pending entry
when the controller is unregistered.

The context also stores a bare hci_conn pointer, so the connection can be
freed while the work is queued. The dequeue in hci_conn_del() does not
cover it either, as it matches on entry->data == conn and entry->data is
the wrapper here. Same problem as commit 2f5d635ad590 ("Bluetooth:
hci_sync: hold conn in hci_connect_acl/le_sync() callbacks").

Hold the connection and release both from a destroy callback. The
submission failure path drops both, since hci_cmd_sync_submit() does not
call the destroy callback when it fails to queue.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash or memory corruption resulting in denial of service
Action: Patch
AI Analysis

Impact

In the Linux kernel Bluetooth subsystem, a flaw in the handling of SCO setup context causes the context not to be freed when a command is cancelled. The leaked entry holds a pointer to a Bluetooth connection that can be freed while the context is still queued, resulting in a use‑after‑free situation. An attacker exploiting this flaw could trigger a kernel crash or memory corruption, leading to denial of service.

Affected Systems

The vulnerability affects the Linux kernel Bluetooth stack across all distributions that use the kernel’s buggy implementation; the specific kernel versions are not enumerated in the data, but it applies to any release that contains the unpatched code.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation so far. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via an external Bluetooth device that initiates a SCO setup and then causes it to be cancelled, exercising the faulty cleanup path. Exploit complexity appears low, relying only on normal Bluetooth operations, but the impact is significant if the kernel crashes.

Generated by OpenCVE AI on September 20, 2026 at 02:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that incorporates the fix, or apply the patch from the kernel repository.
  • If an immediate kernel update is not possible, disable or restrict Bluetooth functionality that uses SCO or block Bluetooth on the affected host.
  • Monitor system logs for kernel panics or unexpected Bluetooth errors and verify that the Bluetooth controller is not unregistered while pending commands exist.

Generated by OpenCVE AI on September 20, 2026 at 02:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-759

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context lifetime hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so the context is only freed if hci_enhanced_setup_sync() actually runs. An entry that is cancelled instead is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. The context also stores a bare hci_conn pointer, so the connection can be freed while the work is queued. The dequeue in hci_conn_del() does not cover it either, as it matches on entry->data == conn and entry->data is the wrapper here. Same problem as commit 2f5d635ad590 ("Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks"). Hold the connection and release both from a destroy callback. The submission failure path drops both, since hci_cmd_sync_submit() does not call the destroy callback when it fails to queue.
Title Bluetooth: hci_conn: fix the SCO setup context lifetime
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:11.196Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.853

Modified: 2026-09-18T18:17:51.010

Link: CVE-2026-90255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses