CVE-2026-23151

CWE-401Memory LeakCWE-7727 documents7 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 96.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix memory leak in set_ssp_complete Fix memory leak in set_ssp_complete() where mgmt_pending_cmd structures are not freed after being removed from the pending list. Commit 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAFs") replaced mgmt_pending_foreach() calls with individual command handling but missed adding mgmt_pending_free() calls in both error and success paths of set_ssp_complete(). Other completion f

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.12.596.12.69+4
CVEListV5linux/linuxd71b98f253b079cbadc83266383f26fe7e9e103b1850a558d116d7e3e2ef36d06a56f59b640cc214+4
Debianlinux< 6.12.69-1+1

Patches

🔴Vulnerability Details

3
OSV
CVE-2026-23151: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix memory leak in set_ssp_complete Fix memory leak in set_ssp_co2026-02-14
CVEList
Bluetooth: MGMT: Fix memory leak in set_ssp_complete2026-02-14
GHSA
GHSA-2chr-7vph-93pf: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix memory leak in set_ssp_complete Fix memory leak in set_ssp_2026-02-14

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Memory leak in Bluetooth MGMT can lead to denial of service2026-02-14
Debian
CVE-2026-23151: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23151 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23151 (MEDIUM CVSS 5.5) | In the Linux kernel | cvebase.io