---
id: CVE-2026-53364
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()

  hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but
  returns 0 without freeing it when nei…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()

  hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but
  returns 0 without freeing it when nei…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-401
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.16.4, < 6.18.35'
  - 'linux_kernel >= 6.19, < 7.0.12'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.12
published: '2026-07-13'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53364'
references:
  - url: 'https://git.kernel.org/stable/c/488e808e3fa53200f3ef3324c45fcba4ae9f4972'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a59d4f4217e6200ca9180643e5738a87d3fa8be0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bfa9d28960ed677d556bdf097073bc3129686229'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e6b78019664dfe37c3dc707f50e7b453d6c7726d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.02554
ingestedAt: '2026-08-03T10:24:20.512Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()

hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but
returns 0 without freeing it when neither pa_sync_term nor big_sync_term
flags are set after evaluating the PA and BIG sync connection state.

This early-return path was introduced when hci_le_big_terminate() was
refactored to take struct hci_conn instead of raw u8 parameters, adding
PA/BIG flag evaluation logic. The existing kfree() on hci_cmd_sync_queue
failure does not cover this path.

## Affected

- `linux_kernel >= 6.16.4, < 6.18.35`
- `linux_kernel >= 6.19, < 7.0.12`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.12`
