PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53252 Linux CVE debrief

CVE-2026-53252 is a memory leak vulnerability in the Linux kernel's Bluetooth HCI UART configuration. The vulnerability occurs when device initialization fails before hci_register_dev() completes, resulting in a leak of percpu memory. This vulnerability has been resolved by explicitly calling cleanup_srcu_struct() in the fallback branch of bt_host_release() before freeing the device. Linux kernel users should review their configurations and ensure they are running the latest kernel version to mitigate this vulnerability.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-07-08
Advisory published
2026-06-25
Advisory updated
2026-07-08

Who should care

Linux kernel users and administrators should be aware of this vulnerability and take necessary steps to mitigate it. This includes reviewing kernel configurations and ensuring the latest kernel version is running. Additionally, defenders should prioritize patching and monitoring for potential exploitation attempts.

Technical summary

The vulnerability occurs in the Linux kernel's Bluetooth HCI UART configuration. When device initialization fails before hci_register_dev() completes, the HCI_UNREGISTER flag is never set. As a result, when the device reference count reaches zero, bt_host_release() evaluates this flag as false and falls back to a direct kfree(hdev). Because hci_release_dev() is bypassed, the SRCU struct initialized early in hci_alloc_dev() is never cleaned up, resulting in a leak of percpu memory. The fix involves explicitly calling cleanup_srcu_struct() in the fallback branch of bt_host_release() before freeing the device.

Defensive priority

High priority should be given to patching this vulnerability, as it could potentially be exploited to cause memory leaks and disrupt system operations. Defenders should prioritize patching and monitoring for potential exploitation attempts.

Recommended defensive actions

  • Review and update Linux kernel configurations to ensure the latest kernel version is running.
  • Prioritize patching and monitoring for potential exploitation attempts.
  • Implement compensating controls to detect and prevent potential exploitation.
  • Monitor system operations for signs of memory leaks or disruptions.
  • Perform regular vulnerability assessments and penetration testing to identify potential weaknesses.

Evidence notes

The vulnerability has been resolved in the Linux kernel, and the fix involves explicitly calling cleanup_srcu_struct() in the fallback branch of bt_host_release() before freeing the device. The CVE record and NVD detail provide additional information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53252 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53252

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53252 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53252

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0622e527a31d4b44737fed5c1a2ac1fc2cfb5184

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/37b3009bf5976e8ab77c8b9a9bc3bbd7ff49e37f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5b7dfca6f852e6b9d809fd0263b5427cc9fb33fd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bc2efe73c194a74839d7cf57b63880d97e21d309

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c016118b9e51eeaf5bc93850d4c455a3b583c0aa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ce4b4cac3c5749b6aa75e62e2991ae2263f2f889

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f82799407a50af7bcacacf09cc9b279af8fe9b81

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.