CVE-2026-53251 is a vulnerability in Linux Kernel
Published on June 25, 2026
Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
hci_get_route() returns a reference-counted hci_dev pointer via
hci_dev_hold(). The function exits normally or with an error without ever
releasing it.
Products Associated with CVE-2026-53251
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1360e5b6ce63d63d23223a659ca2bbafa30a53aa and below 4bbec25f47b930101294fd310c627c3f53e9661f is affected.
- Version 07a9342b94a91b306ed1cf6aa8254aea210764c9 and below 33d677d2e3713d98012c3dbd4a9207f7d785b854 is affected.
- Version 07a9342b94a91b306ed1cf6aa8254aea210764c9 and below 23e8eb16820b866528fb300dc67fe3f67f00ef62 is affected.
- Version 07a9342b94a91b306ed1cf6aa8254aea210764c9 and below 5cbf290b79351971f20c7a533247e8d58a3f970c is affected.
- Version bfec1e55314896bf4a4cfdb3a9ad4872be9f06ed is affected.
- Version 6.12.2 and below 6.12.94 is affected.
- Version 6.11.11 and below 6.12 is affected.
- Version 6.13 is affected.
- Before 6.13 is unaffected.
- Version 6.12.94, <= 6.12.* is unaffected.
- Version 6.18.36, <= 6.18.* is unaffected.
- Version 7.0.13, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.