CVE-2026-53251
Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_route() returns a reference-counted hci_dev pointer via hci_dev_hold(). The function exits normally or with an error without ever releasing it.
INFO
Published Date :
June 25, 2026, 9:16 a.m.
Last Modified :
July 8, 2026, 4:51 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Apply the patch to release the hci_dev reference.
- Update the Linux kernel to the fixed version.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53251.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53251 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53251
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53251 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53251 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE CWE-772 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.11.11 up to (excluding) 6.12 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.12.2 up to (excluding) 6.12.94 Added Reference Type kernel.org: https://git.kernel.org/stable/c/23e8eb16820b866528fb300dc67fe3f67f00ef62 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/33d677d2e3713d98012c3dbd4a9207f7d785b854 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/4bbec25f47b930101294fd310c627c3f53e9661f Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/5cbf290b79351971f20c7a533247e8d58a3f970c Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '1360e5b6ce63d63d23223a659ca2bbafa30a53aa', 'lessThan': '4bbec25f47b930101294fd310c627c3f53e9661f', 'versionType': 'git'}, {'status': 'affected', 'version': '07a9342b94a91b306ed1cf6aa8254aea210764c9', 'lessThan': '33d677d2e3713d98012c3dbd4a9207f7d785b854', 'versionType': 'git'}, {'status': 'affected', 'version': '07a9342b94a91b306ed1cf6aa8254aea210764c9', 'lessThan': '23e8eb16820b866528fb300dc67fe3f67f00ef62', 'versionType': 'git'}, {'status': 'affected', 'version': '07a9342b94a91b306ed1cf6aa8254aea210764c9', 'lessThan': '5cbf290b79351971f20c7a533247e8d58a3f970c', 'versionType': 'git'}, {'status': 'affected', 'version': 'bfec1e55314896bf4a4cfdb3a9ad4872be9f06ed', 'versionType': 'git'}, {'status': 'affected', 'version': '6.12.2', 'lessThan': '6.12.94', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.11.11', 'lessThan': '6.12', 'versionType': 'semver'}], 'programFiles': ['net/bluetooth/iso.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.13'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.13', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/iso.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_route() returns a reference-counted hci_dev pointer via hci_dev_hold(). The function exits normally or with an error without ever releasing it. Added Reference https://git.kernel.org/stable/c/23e8eb16820b866528fb300dc67fe3f67f00ef62 Added Reference https://git.kernel.org/stable/c/33d677d2e3713d98012c3dbd4a9207f7d785b854 Added Reference https://git.kernel.org/stable/c/4bbec25f47b930101294fd310c627c3f53e9661f Added Reference https://git.kernel.org/stable/c/5cbf290b79351971f20c7a533247e8d58a3f970c