Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the HCI command when it is cancelled

mgmt_hci_cmd_sync() queues the pending command with a NULL destroy
callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled
entry is leaked, as _hci_cmd_sync_cancel_entry() does not release
entry->data when there is no destroy callback, and hci_cmd_sync_clear()
cancels every pending entry when the controller is unregistered. Nothing
else reclaims it either: mgmt_pending_new() does not put the command on
hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so
the mgmt socket is never released.

Free the command from a destroy callback. The now-empty done label is
replaced by a direct return.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak (Memory and socket reference)
Action: Patch
AI Analysis

Impact

In the Linux kernel Bluetooth management layer, the function mgmt_hci_cmd_sync enqueues HCI commands that are meant to be freed after completion. The implementation does not provide a destroy callback for cancelled commands, causing each cancelled entry and its associated data to remain allocated. Additionally, the socket reference that mgmt_pending_new() acquires is never released when the command leaks, preventing the management socket from being closed. The result is a memory and resource leak that can grow without bound, potentially exhausting system memory or leading to unavailable Bluetooth services.

Affected Systems

The vulnerability affects all Linux kernel releases that contain the buggy mgmt_hci_cmd_sync and mgmt_pending_new implementations and have not yet incorporated the commits identified in the linked Git history (c/414b365e, c/481533b, c/e0cd7b34). No explicit version numbers are provided; the fix is documented in the commit messages and is available in kernel versions shipped after the patch is merged.

Risk and Exploitability

The EPSS score for this issue is reported as less than 1 % and it is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. Nevertheless, an attacker with local privileges or access to Bluetooth traffic could trigger the bug by cancelling pending HCI commands, leading to a gradual increase in memory and socket handle usage. Because the exploit remains within the local kernel context and requires only normal device operations, the feasibility is moderate but the impact is limited to stability rather than immediate denial of service. System administrators should treat this as a medium risk followed by patching to restore proper cleanup behavior.

Generated by OpenCVE AI on September 19, 2026 at 03:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch commits c/414b365e, c/481533b, and c/e0cd7b34 which add a destroy callback for cancelled HCI commands.
  • If an immediate kernel update is not possible, temporarily disable the Bluetooth MGMT subsystem or block new Bluetooth device registrations to prevent the memory leak from occurring.
  • After the patch is applied, monitor system memory usage and socket counts for the Bluetooth mgmt socket to verify that the leak no longer persists.

Generated by OpenCVE AI on September 19, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is cancelled mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending. The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released. Free the command from a destroy callback. The now-empty done label is replaced by a direct return.
Title Bluetooth: MGMT: free the HCI command when it is cancelled
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:52.738Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.500

Modified: 2026-09-17T17:17:21.500

Link: CVE-2026-90252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:08Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime