Impact
In the Linux kernel Bluetooth management layer, the function mgmt_hci_cmd_sync enqueues HCI commands that are meant to be freed after completion. The implementation does not provide a destroy callback for cancelled commands, causing each cancelled entry and its associated data to remain allocated. Additionally, the socket reference that mgmt_pending_new() acquires is never released when the command leaks, preventing the management socket from being closed. The result is a memory and resource leak that can grow without bound, potentially exhausting system memory or leading to unavailable Bluetooth services.
Affected Systems
The vulnerability affects all Linux kernel releases that contain the buggy mgmt_hci_cmd_sync and mgmt_pending_new implementations and have not yet incorporated the commits identified in the linked Git history (c/414b365e, c/481533b, c/e0cd7b34). No explicit version numbers are provided; the fix is documented in the commit messages and is available in kernel versions shipped after the patch is merged.
Risk and Exploitability
The EPSS score for this issue is reported as less than 1 % and it is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. Nevertheless, an attacker with local privileges or access to Bluetooth traffic could trigger the bug by cancelling pending HCI commands, leading to a gradual increase in memory and socket handle usage. Because the exploit remains within the local kernel context and requires only normal device operations, the feasibility is moderate but the impact is limited to stability rather than immediate denial of service. System administrators should treat this as a medium risk followed by patching to restore proper cleanup behavior.
OpenCVE Enrichment