Answer in brief
CVE-2026-90088 records a Unknown severity vulnerability in Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e7c0aa45ae6c5a338661b23812bfcdef50bf3e96 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <cbc2962da99b6b89345267d3aa74b4b573340548 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9b2e5f1928c99224345a9ed8c5dae5fc74964d6d || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <fc4851ff8dfb505e9a19efcc286712132bbd178d || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f561e44261344adadf9d6a6dff31e3af9776d5c6 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <aeee917a4878af95f0c63e18c5f22eaf6299c7b8 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3988cbb1be501dbff909a2ee024670e3c955a66d || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <44c98fd082eafd49d55a8a4077ff488175b2fe24 | e7c0aa45ae6c5a338661b23812bfcdef50bf3e96, cbc2962da99b6b89345267d3aa74b4b573340548, 9b2e5f1928c99224345a9ed8c5dae5fc74964d6d, fc4851ff8dfb505e9a19efcc286712132bbd178d, f561e44261344adadf9d6a6dff31e3af9776d5c6, aeee917a4878af95f0c63e18c5f22eaf6299c7b8, 3988cbb1be501dbff909a2ee024670e3c955a66d, 44c98fd082eafd49d55a8a4077ff488175b2fe24 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop rfcomm_apply_pn() accepts the MTU value from a remote PN (Parameter Negotiation) frame without checking for zero. When the remote peer sends an MTU of zero, d->mtu is set to 0. This causes the sendmsg path to enter an infinite loop when fragmenting data, as each fragment has size == min_t(size_t, len, 0) == 0, so the remaining length never decreases. The infinite allocation of zero-length skbs exhausts all system memory. Fix by clamping d->mtu to RFCOMM_DEFAULT_MTU when the negotiated value is zero, consistent with the initial value assigned in rfcomm_dlc_alloc().
Quoted source text, attributed separately from HOL analysis.