Memory leak in Linux kernel - CVE-2026-90252
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource cleanup in the Bluetooth management HCI command synchronization handler when a pending HCI command is canceled. A local user can issue a management HCI command synchronization request to cause a denial of service.
Controller unregistration cancels all pending command entries.