Junglewise Threat Intelligence

CVE-2026-90087: Linux kernel Bluetooth LE connection leak on rejection

CVE-2026-90087 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth subsystem leaks connection resources when a second LE (Low Energy / BLE) connection attempt is rejected by the controller. This causes subsequent Bluetooth connection attempts to fail indefinitely, effectively disabling LE connectivity until the adapter is reset. While this impacts device connectivity and user experience, there is no direct security impact such as data compromise or unauthorized access.

Technical details

The vulnerability exists in the create_le_conn_complete() handler, which incorrectly handles concurrent LE connection attempts. When two connections are pending in BT_CONNECT state, hci_lookup_le_connect() may return a different connection than the one being reported as failed, causing the error handler (hci_conn_failed()) to be skipped. The controller rejects a second HCI_OP_LE_CREATE_CONN command while another is outstanding (per Bluetooth Core Spec Vol 4, Part E), but some controllers (e.g., bcm43438) return LMP/LL error codes instead of the spec-mandated Command Disallowed response. The leaked connection remains in BT_CONNECT state indefinitely, and subsequent hci_connect_le() calls refuse to proceed because hci_lookup_le_connect() still finds the stale connection. The fix changes the lookup from device-centric to connection-centric comparison to correctly match the failing connection.

Affected products

  • Linux Linux kernel <unknown>

Timeline

  • 2026-09-17: disclosed
  • other: Vulnerability resolved in kernel commit

Related threats