Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-90087
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper connection state validation in create_le_conn_complete() when handling rejection of a second LE connection while another LE connection is pending. A local user can initiate concurrent LE connection attempts to cause a denial of service.