PatchSiren cyber security CVE debrief
CVE-2026-72333 Linux CVE debrief
The Linux kernel's Bluetooth L2CAP has a vulnerability where tx idents leak for commands without a response. This causes identifiers to be allocated but never released, potentially leading to exhaustion of the ident range and sending L2CAP_LE_CREDITS packets with an invalid ident of 0. The issue was fixed by releasing idents immediately after sending L2CAP_LE_CREDITS. Affected product deployments should be reviewed for potential exposure, and owners should be assigned for follow-up. The vulnerability has a significant impact on Linux kernel users, Bluetooth developers, and organizations using Linux-based systems with Bluetooth capabilities.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel users, Bluetooth developers, and organizations using Linux-based systems with Bluetooth capabilities should be aware of this vulnerability and take steps to mitigate it. The vulnerability has a significant impact on system security, and affected product deployments should be reviewed for potential exposure. Owners should be assigned for follow-up, and compensating controls should be implemented for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. System administrators and security teams should prioritize patching and mitigation efforts to prevent potential exploitation. Additionally, asset inventory and vulnerability management teams should be informed to ensure that affected systems are properly tracked and prioritized for remediation. Security teams should also review and update their incident response plans to address potential exploitation of this vulnerability. Compensating controls, such as monitoring and detection, should be implemented to detect and respond to potential exploitation attempts. Rollback and change windows should be planned and implemented to ensure that patches are applied in a timely and controlled manner. Source tracking and verification should be performed to ensure that affected systems are properly identified and remediated. Overall, a coordinated and proactive approach is necessary to address this vulnerability and prevent potential exploitation. It is also recommended to verify Linux kernel version and apply latest Bluetooth L2CAP updates, monitor system logs for Bluetooth L2CAP errors, and implement compensating controls for Bluetooth communication. System administrators should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is and
Technical summary
The Linux kernel's Bluetooth L2CAP has a vulnerability where tx idents leak for commands without a response. This causes identifiers to be allocated but never released, potentially leading to exhaustion of the ident range and sending L2CAP_LE_CREDITS packets with an invalid ident of 0. The issue was fixed by releasing idents immediately after sending L2CAP_LE_CREDITS. The vulnerability affects Linux kernel users, Bluetooth developers, and organizations using Linux-based systems with Bluetooth capabilities. The issue has a significant impact on system security and should be addressed promptly.
Defensive priority
Linux kernel users should verify their systems are updated with the latest Bluetooth L2CAP fixes to prevent potential tx ident leaks.
Recommended defensive actions
- Verify Linux kernel version and apply latest Bluetooth L2CAP updates
- Monitor system logs for Bluetooth L2CAP errors
- Implement compensating controls for Bluetooth communication
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE details a tx ident leak in the Linux kernel's Bluetooth L2CAP for commands without a response. Identifiers allocated for such commands are never released, leading to potential exhaustion of the 1-255 ident range. This issue can cause L2CAP_LE_CREDITS packets to be sent with an invalid ident of 0, dropping these commands by remote stacks that validate the ident. The issue was resolved by releasing the ident immediately after sending L2CAP_LE_CREDITS.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72333 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72333
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72333 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72333
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0c602cb8f148a36bfb39c25ade400bdadc023c4f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e1930ece855a4c256f1c7e6632d634cfb9888b5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b8a32a5fc915b024c60f18d51b6cffd2bd64d4a6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bd1e01170341291292fd4c46b5f6949da282ca6c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d0a2b0c81f112540a337cde1c20251bf05ddf1da
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.