CVE-2026-90254 | Linux Kernel up to 7.2.5 hci_sync adv_timeout_expire memory leak
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.51/7.2.5. This vulnerability affects the function adv_timeout_expire of the component hci_sync. The manipulation results in memory leak.
This vulnerability is cataloged as CVE-2026-90254. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.