Junglewise Threat Intelligence

CVE-2026-53364: Linux Kernel memory leak in Bluetooth hci_le_big_terminate

CVE-2026-53364 · Severity: info · CVSS 2.1 · Published 2026-07-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's Bluetooth subsystem. The issue occurs when the system fails to release memory during the termination of certain Bluetooth Low Energy (LE) Broadcast Isochronous Group (BIG) connections. Over time, repeated triggers of this flaw could lead to system instability or performance degradation as available memory is exhausted.

Technical details

A memory leak exists in the hci_le_big_terminate() function within net/bluetooth/hci_conn.c. The function allocates memory for 'iso_list_data' using kzalloc_obj but fails to free it during an early-return path when neither 'pa_sync_term' nor 'big_sync_term' flags are set. This logic error was introduced during a refactoring of the function to handle struct hci_conn parameters. An attacker with local access could potentially trigger this path repeatedly to exhaust kernel memory. The issue has been resolved by adding a kfree() call to the affected early-return path in stable kernel branches.

Affected products

  • Linux Linux Kernel 6.16.4 to 6.17, 6.18.35, 7.0.12

Timeline

  • 2026-05-21: other: Vulnerability fixed in upstream commits
  • 2026-07-13: advisory: CVE published and NVD record created

References

Related threats