Junglewise Threat Intelligence

CVE-2026-63948: Linux Kernel Bluetooth L2CAP reference leak in l2cap_chan_timeout

CVE-2026-63948 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth component that could lead to a resource leak. Specifically, the system fails to properly release memory references during certain Bluetooth connection timeouts. Over time, this could lead to system instability or a denial-of-service condition as system resources are exhausted.

Technical details

A reference leak exists in the l2cap_chan_timeout() function within the Linux kernel's Bluetooth L2CAP core. The function __set_chan_timer() increments the reference count of an l2cap_chan object via l2cap_chan_hold() before scheduling delayed work. While the standard execution path correctly decrements this count using l2cap_chan_put(), an early return path triggered when the connection object (chan->conn) is NULL fails to release the reference. This results in a memory/reference leak. The issue has been patched across multiple stable kernel branches by ensuring l2cap_chan_put() is called before the early return.

Affected products

  • Linux Linux Kernel 5.10.217 to 5.10.259, 5.15.159 to 5.15.210, 6.1.91 to 6.1.176, 6.6.31 to 6.6.143

Timeline

  • 2026-05-20: other: Vulnerability fixed in source code
  • 2026-07-19: disclosed: CVE published

References