CVE-2026-90256

8.8

Linux · Kernel

A use-after-free vulnerability in the Linux kernel Bluetooth L2CAP subsystem allows unauthenticated adjacent attackers to trigger memory corruption and potential code execution.

Executive summary

A high-severity use-after-free vulnerability in the Linux kernel Bluetooth L2CAP subsystem poses a significant risk of system compromise to adjacent users.

Vulnerability

The vulnerability exists in the hci_conn::l2cap_data handling logic, where an improper locking mechanism allows for a use-after-free condition during concurrent connection disconnection. This flaw is reachable by unauthenticated, adjacent attackers via the Bluetooth protocol.

Business impact

Successful exploitation of this use-after-free flaw can lead to arbitrary code execution, denial of service, or total system compromise. Given the CVSS score of 8.8, this vulnerability is categorized as High severity and represents a significant risk to the integrity and availability of any Linux-based device with active Bluetooth connectivity.

Remediation

Immediate Action: Update the Linux kernel to version 7.2.6 or the relevant stable branch version (6.7, 6.13, or 6.14) provided by your distribution vendor.

Proactive Monitoring: Monitor Bluetooth traffic for anomalous connection patterns or frequent service crashes that may indicate exploitation attempts.

Compensating Controls: If patching is not immediately feasible, disable the Bluetooth subsystem on affected devices to remove the attack vector entirely.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk posed by this kernel-level vulnerability is severe, particularly for mobile or IoT devices where Bluetooth remains enabled. Administrators should prioritize the deployment of kernel security updates across all affected systems to remediate this memory corruption flaw and prevent potential remote exploitation.

More Linux CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources