-

CVE-2026-90253

Bluetooth: MGMT: free the mesh send cancel command when it is cancelled

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the mesh send cancel command when it is cancelled

mesh_send_cancel() queues the pending command with a NULL destroy
callback, so it is only freed if send_cancel() runs. A cancelled entry is
leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when
there is no destroy callback, and hci_cmd_sync_clear() cancels every
pending entry when the controller is unregistered. Nothing else reclaims
it either: mgmt_pending_new() does not put the command on
hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so
the mgmt socket is never released.

Free the command from a destroy callback.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < b609341ee56967d9a45845ff26f79336d2114b55
Status affected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < 416fabca9b7237b76aa9cafcf8c497b8ac00d88c
Status affected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < 88e30d036d777b00aed42bd35000de23ff40910c
Status affected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < 05438d338a875a9daa08ca3f6a35b4480cf13de4
Status affected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < fa46d428c014e7b72a18634679815670418e67dc
Status affected
Version b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Version < 3c742feda8fcabf741a17bcf668b63c8f606f9c5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.1
Status affected
Version 0
Version < 6.1
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b609341ee56967d9a45845ff26f79336d2114b55
https://git.kernel.org/stable/c/416fabca9b7237b76aa9cafcf8c497b8ac00d88c
https://git.kernel.org/stable/c/88e30d036d777b00aed42bd35000de23ff40910c
https://git.kernel.org/stable/c/05438d338a875a9daa08ca3f6a35b4480cf13de4
https://git.kernel.org/stable/c/fa46d428c014e7b72a18634679815670418e67dc
https://git.kernel.org/stable/c/3c742feda8fcabf741a17bcf668b63c8f606f9c5