CVE-2026-90253

Source
https://cve.org/CVERecord?id=CVE-2026-90253
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90253.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90253
Downstream
Published
2026-09-17T16:07:53Z
Modified
2026-09-18T03:48:36Z
Summary
Bluetooth: MGMT: free the mesh send cancel command when it is cancelled
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the mesh send cancel command when it is cancelled

mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_cancel() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released.

Free the command from a destroy callback.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90253.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b338d91703fae6f6afd67f3f75caa3b8f36ddef3
Fixed
b609341ee56967d9a45845ff26f79336d2114b55
Fixed
416fabca9b7237b76aa9cafcf8c497b8ac00d88c
Fixed
88e30d036d777b00aed42bd35000de23ff40910c
Fixed
05438d338a875a9daa08ca3f6a35b4480cf13de4
Fixed
fa46d428c014e7b72a18634679815670418e67dc
Fixed
3c742feda8fcabf741a17bcf668b63c8f606f9c5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90253.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90253.json"