« Volver al listado

CVE-2026-90252

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the HCI command when it is cancelled

mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released.

Leer descripción completaMostrar menos

Free the command from a destroy callback. The now-empty done label is replaced by a direct return.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90252",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "827af4787e74e8df9e8e0677a69fbb15e0856d2f",
              "lessThan": "e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "827af4787e74e8df9e8e0677a69fbb15e0856d2f",
              "lessThan": "481533b03985177ddc805e0bd12fc07e7adf9040",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "827af4787e74e8df9e8e0677a69fbb15e0856d2f",
              "lessThan": "414b365ecea6c30357adee6b8a7c5edc03a03575",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/mgmt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:21.500",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/414b365ecea6c30357adee6b8a7c5edc03a03575",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/481533b03985177ddc805e0bd12fc07e7adf9040",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: free the HCI command when it is cancelled\n\nmgmt_hci_cmd_sync() queues the pending command with a NULL destroy\ncallback, so it is only freed if send_hci_cmd_sync() runs. A cancelled\nentry is leaked, as _hci_cmd_sync_cancel_entry() does not release\nentry->data when there is no destroy callback, and hci_cmd_sync_clear()\ncancels every pending entry when the controller is unregistered. Nothing\nelse reclaims it either: mgmt_pending_new() does not put the command on\nhdev->mgmt_pending.\n\nThe leak also pins the socket reference taken by mgmt_pending_new(), so\nthe mgmt socket is never released.\n\nFree the command from a destroy callback. The now-empty done label is\nreplaced by a direct return."
    }
  ],
  "lastModified": "2026-09-17T17:17:21.500",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}