๐Ÿ” CVE Alert

CVE-2026-90252

UNKNOWN 0.0

Bluetooth: MGMT: free the HCI command when it is cancelled

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is cancelled mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending. The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released. Free the command from a destroy callback. The now-empty done label is replaced by a direct return.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
827af4787e74e8df9e8e0677a69fbb15e0856d2f < e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93 827af4787e74e8df9e8e0677a69fbb15e0856d2f < 481533b03985177ddc805e0bd12fc07e7adf9040 827af4787e74e8df9e8e0677a69fbb15e0856d2f < 414b365ecea6c30357adee6b8a7c5edc03a03575
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93 git.kernel.org: https://git.kernel.org/stable/c/481533b03985177ddc805e0bd12fc07e7adf9040 git.kernel.org: https://git.kernel.org/stable/c/414b365ecea6c30357adee6b8a7c5edc03a03575