Junglewise Threat Intelligence

CVE-2026-72334: Linux kernel Bluetooth ISO packet handling denial of service

CVE-2026-72334 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth ISO (Isochronous) packet handler has multiple bugs in how it processes packet fragment sequences from Bluetooth controllers. A malicious or malfunctioning Bluetooth device can trigger memory leaks, kernel panics, or cause the system to accept malformed data, potentially leading to service disruption or data corruption in any system using Bluetooth audio or isochronous data streams.

Technical details

The vulnerability exists in the net/bluetooth/iso.c module's iso_recv() function, which handles reassembly of fragmented Bluetooth ISO packets using ISO_START, ISO_CONT, and ISO_END packet types. The root causes include: (1) improper tracking of unfinished packet assembly state, allowing memory leaks when ISO_CONT arrives after incomplete ISO_START; (2) missing length validation before calling skb_put(), which can cause kernel panics on oversized ISO_END packets; and (3) accepting undersized ISO_END packets that should be rejected. The attack vector requires a malicious or compromised Bluetooth device to send malformed packet sequences. No authentication or user interaction is required—exploitation occurs automatically during normal Bluetooth ISO data reception. Patches were applied to consolidate ISO_CONT and ISO_END handling, enforce proper state checks via conn->rx_skb, and validate packet lengths before memory operations.

Affected products

  • Linux Linux kernel Multiple stable branches (2.6.11–7.2 and rolling)

Timeline

  • 2026-08-15: disclosed: CVE-2026-72334 published
  • 2026-09-21: patched: Upstream fix commit e054c1a6ae7310d2815778fddb87da616e11c255; backported to stable branches

References

Related threats