CVE-2026-53251
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_route() returns a reference-counted hci_dev pointer via hci_dev_hold(). The function exits normally or with an error without ever releasing it.
- Published Jun 25, 2026
- CVSS 5.5 medium
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available