Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth component that could lead to a resource leak. Specifically, the system fails to properly release memory references during certain Bluetooth connection timeouts. Over time, this could lead to system instability or a denial-of-service condition as system resources are exhausted.
Technical details
A reference leak exists in the l2cap_chan_timeout() function within the Linux kernel's Bluetooth L2CAP core. The function __set_chan_timer() increments the reference count of an l2cap_chan object via l2cap_chan_hold() before scheduling delayed work. While the standard execution path correctly decrements this count using l2cap_chan_put(), an early return path triggered when the connection object (chan->conn) is NULL fails to release the reference. This results in a memory/reference leak. The issue has been patched across multiple stable kernel branches by ensuring l2cap_chan_put() is called before the early return.
Affected products
- Linux Linux Kernel 5.10.217 to 5.10.259, 5.15.159 to 5.15.210, 6.1.91 to 6.1.176, 6.6.31 to 6.6.143
Timeline
- 2026-05-20: other: Vulnerability fixed in source code
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/08d81fe96f80a8e20c7acb573b6a45d901fcf2cd
- https://git.kernel.org/stable/c/107c826e4ef9ec5ad8f60e6fe64d8d5325ba508f
- https://git.kernel.org/stable/c/50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee
- https://git.kernel.org/stable/c/63cd225cc13d782a85e2a73c04d0d350153eada1
- https://git.kernel.org/stable/c/8894c2010435a56ce7c6c2a8785860c13554df2f
- https://git.kernel.org/stable/c/9dbd84990394c51f5cee1e8871bb5ff8af5ed939
- https://git.kernel.org/stable/c/b5c59a5b469e2a809a2d57eda4ded94235971060