In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
References
Configurations
Configuration 1 (hide)
|
History
29 May 2026, 14:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/21e4271e65094172aadd5beb8caea95dd0fbf6d7 - Patch | |
| References | () https://git.kernel.org/stable/c/2b6c942a526635f5c61d2f000258e620da32d3a7 - Patch | |
| References | () https://git.kernel.org/stable/c/3de7c10a950b36affc692d8bd2ac713852580e56 - Patch | |
| Summary |
|
|
| CWE | CWE-772 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Linux
Linux linux Kernel |
|
| CPE | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
25 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 11:16
Updated : 2026-05-29 14:25
NVD link : CVE-2026-23299
Mitre link : CVE-2026-23299
CVE.ORG link : CVE-2026-23299
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-772
Missing Release of Resource after Effective Lifetime
