Memory leak in Linux kernel - CVE-2026-90254
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a memory leak.
The vulnerability exists due to improper release of memory in Bluetooth HCI synchronous command queue handling when an advertising timeout expires and a command cannot be queued or a pending entry is canceled. A local user can trigger advertising timeout handling under these conditions to cause a memory leak.
Affected software
How to mitigate CVE-2026-90254
External References
- https://git.kernel.org/stable/c/120d8dc042e3d45073bb6e50ee7b058a0b182627
- https://git.kernel.org/stable/c/193182c6467f508a8a61d5db506d796ffed6eee6
- https://git.kernel.org/stable/c/2e3d827cd56865c14f6ca118bbccd7801091fb21
- https://git.kernel.org/stable/c/9c3b6c1413bd0b4993642d987616331f84d9b7f5
- https://git.kernel.org/stable/c/bb5ca1cc7744c41c59002bd6523714a685ae6595
- https://git.kernel.org/stable/c/c2019224a766245b7db39d87fdfe84c3fdc879d9