Home

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, or if the controller is removed unexpectedly, these SKBs will leak. Fix by adding skb_queue_purge() calls for sk_error_queue in affected bluetooth destructors. RFCOMM does not currently use sk_error_queue.

PUBLISHED Reserved 2026-01-13 | Published 2026-03-25 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

134f4b39df7b77225a80ef585c15d46f964f5e6f (git) before 2b6c942a526635f5c61d2f000258e620da32d3a7
affected

134f4b39df7b77225a80ef585c15d46f964f5e6f (git) before 3de7c10a950b36affc692d8bd2ac713852580e56
affected

134f4b39df7b77225a80ef585c15d46f964f5e6f (git) before 21e4271e65094172aadd5beb8caea95dd0fbf6d7
affected

Default status
affected

6.15
affected

Any version before 6.15
unaffected

6.18.17 (semver)
unaffected

6.19.7 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/2b6c942a526635f5c61d2f000258e620da32d3a7

git.kernel.org/...c/3de7c10a950b36affc692d8bd2ac713852580e56

git.kernel.org/...c/21e4271e65094172aadd5beb8caea95dd0fbf6d7

cve.org (CVE-2026-23299)

nvd.nist.gov (CVE-2026-23299)

Download JSON