news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-23151

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
6.1 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
EPSS
0.11%
Risk score
1.0
Published
2026-02-14
Status
Published

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix memory leak in set_ssp_complete Fix memory leak in set_ssp_complete() where mgmt_pending_cmd structures are not freed after being removed from the pending list. Commit 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAFs") replaced mgmt_pending_foreach() calls with individual command handling but missed adding mgmt_pending_free() calls in both error and success paths of set_ssp_complete(). Other completion functions like set_le_complete() were fixed correctly in the same commit. This causes a memory leak of the mgmt_pending_cmd structure and its associated parameter data for each SSP command that completes. Add the missing mgmt_pending_free(cmd) calls in both code paths to fix the memory leak. Also fix the same issue in set_advertising_complete(). A flaw was found in the Linux kernel's Bluetooth Management (MGMT) component. This vulnerability, a memory leak, allows a local user with elevated privileges to cause the kernel to consume an increasing amount of memory. The issue stems from mgmt_pending_cmd structures not being properly released after certain Bluetooth operations. Over time, this can lead to system instability, resource exhaustion, and ultimately a denial of service, making the system unavailable.

Weaknesses

CWE-772

Coverage 3

Advisories and references