CVE-2026-63948: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn __set_chan_timer() takes a l2cap_chan reference via l2cap_chan_hold() before scheduling the delayed work. The normal path in l2cap_chan_timeout() drops this reference with l2cap_chan_put() at the end, but the early return when chan->conn is NULL skips the put, leaking the reference. Add the missing l2cap_chan_put() before the early return.
Affected products
- Linux Linux: from 5.10.217, before 5.10.259 (fixed in 5.10.259); from 5.15.159, before 5.15.210 (fixed in 5.15.210); from 6.1.91, before 6.1.176 (fixed in 6.1.176); from 6.6.31, before 6.6.143 (fixed in 6.6.143); from 4.19.314, before 4.20 (fixed in 4.20); from 5.4.276, before 5.5 (fixed in 5.5); …
Published 2026-07-19. Last modified 2026-07-27.