CVE-2026-53251 PUBLISHED

Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync

Assigner: Linux
Reserved: 09.06.2026 Published: 25.06.2026 Updated: 25.06.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync

hci_get_route() returns a reference-counted hci_dev pointer via hci_dev_hold(). The function exits normally or with an error without ever releasing it.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1360e5b6ce63d63d23223a659ca2bbafa30a53aa to 4bbec25f47b930101294fd310c627c3f53e9661f (excl.)
  • affected from 07a9342b94a91b306ed1cf6aa8254aea210764c9 to 33d677d2e3713d98012c3dbd4a9207f7d785b854 (excl.)
  • affected from 07a9342b94a91b306ed1cf6aa8254aea210764c9 to 23e8eb16820b866528fb300dc67fe3f67f00ef62 (excl.)
  • affected from 07a9342b94a91b306ed1cf6aa8254aea210764c9 to 5cbf290b79351971f20c7a533247e8d58a3f970c (excl.)
  • Version bfec1e55314896bf4a4cfdb3a9ad4872be9f06ed is affected
  • affected from 6.12.2 to 6.12.94 (excl.)
  • affected from 6.11.11 to 6.12 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.13 is affected
  • unaffected from 0 to 6.13 (excl.)
  • unaffected from 6.12.94 to 6.12.* (incl.)
  • unaffected from 6.18.36 to 6.18.* (incl.)
  • unaffected from 7.0.13 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References