Impact
The flaw occurs in the Bluetooth management layer of the Linux kernel where a mesh send cancel command is not properly freed when cancelled. This leads to a memory leak and a leaked socket reference that is never released. If an attacker can trigger the repeated creation of such commands, the kernel may exhaust memory or other resources, potentially causing instability or a system crash. The impact is limited to the local machine as the vulnerability does not directly reveal data but can lead to denial of service through resource exhaustion.
Affected Systems
The vulnerability affects the Linux kernel’s Bluetooth (MGMT) subsystem. No specific kernel release is listed in the advisory and the extraction does not provide patch version information. Any Linux kernel running Bluetooth mesh support and lacking the recent fix is affected.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation. However, an attacker would need the ability to send Bluetooth management packets to target the mesh send cancel mechanism, which could be achieved locally or remotely if Bluetooth services are exposed. The risk is therefore moderate from a potential DoS perspective. Applying the official kernel patch is the only known mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA