Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the mesh send cancel command when it is cancelled

mesh_send_cancel() queues the pending command with a NULL destroy
callback, so it is only freed if send_cancel() runs. A cancelled entry is
leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when
there is no destroy callback, and hci_cmd_sync_clear() cancels every
pending entry when the controller is unregistered. Nothing else reclaims
it either: mgmt_pending_new() does not put the command on
hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so
the mgmt socket is never released.

Free the command from a destroy callback.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

The flaw occurs in the Bluetooth management layer of the Linux kernel where a mesh send cancel command is not properly freed when cancelled. This leads to a memory leak and a leaked socket reference that is never released. If an attacker can trigger the repeated creation of such commands, the kernel may exhaust memory or other resources, potentially causing instability or a system crash. The impact is limited to the local machine as the vulnerability does not directly reveal data but can lead to denial of service through resource exhaustion.

Affected Systems

The vulnerability affects the Linux kernel’s Bluetooth (MGMT) subsystem. No specific kernel release is listed in the advisory and the extraction does not provide patch version information. Any Linux kernel running Bluetooth mesh support and lacking the recent fix is affected.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation. However, an attacker would need the ability to send Bluetooth management packets to target the mesh send cancel mechanism, which could be achieved locally or remotely if Bluetooth services are exposed. The risk is therefore moderate from a potential DoS perspective. Applying the official kernel patch is the only known mitigation.

Generated by OpenCVE AI on September 19, 2026 at 03:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the Bluetooth MGMT memory‑leak fix
  • If Bluetooth mesh is not required, disable the mesh subsystem or firewall Bluetooth management traffic
  • Watch for backport/firmware updates from distributors that address the issue
  • Ensure the kernel is rebuilt with MMU protection or a memory‑leak detector to catch similar issues

Generated by OpenCVE AI on September 19, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command when it is cancelled mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_cancel() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending. The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released. Free the command from a destroy callback.
Title Bluetooth: MGMT: free the mesh send cancel command when it is cancelled
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:53.435Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.607

Modified: 2026-09-17T17:17:21.607

Link: CVE-2026-90253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-401

    Missing Release of Memory after Effective Lifetime