CVE-2026-23299
published 2026-03-25CVE-2026-23299: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 134f4b39df7b77225a80ef585c15d46f964f5e6f < 2b6c942a526635f5c61d2f000258e620da32d3a7 | 2b6c942a526635f5c61d2f000258e620da32d3a7 |
| linux | linux | >= 134f4b39df7b77225a80ef585c15d46f964f5e6f < 3de7c10a950b36affc692d8bd2ac713852580e56 | 3de7c10a950b36affc692d8bd2ac713852580e56 |
| linux | linux | >= 134f4b39df7b77225a80ef585c15d46f964f5e6f < 21e4271e65094172aadd5beb8caea95dd0fbf6d7 | 21e4271e65094172aadd5beb8caea95dd0fbf6d7 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.15 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.15.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat3.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Bluetooth: purge error queues in socket destructors
vendor_redhat·2026-03-25·CVSS 3.3
CVE-2026-23299 [MEDIUM] CWE-772 kernel: Bluetooth: purge error queues in socket destructors
kernel: Bluetooth: purge error queues in socket destructors
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
A flaw was found in the Linux kernel's Bluetooth subsystem. When transmit (TX) timestamping is enabled, socket kernel buffers (SKBs) can accumulate in an error queue. If user applications fail to read these timestamps or if the Bluetoot
Debian
CVE-2026-23299: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
vendor_debian·2026
CVE-2026-23299 [LOW] CVE-2026-23299: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, or if the controller is removed unexpectedly, these SKBs will leak. Fix by adding skb_queue_purge() calls for sk_error_queue in affected bluetooth destructors. RFCOMM does not currently use sk_error_queue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: resolved
VulDB
Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 Bluetooth skb_queue_purge release of resource (WID-SEC-2026-0861)
vuldb·2026-06-01·CVSS 5.5
CVE-2026-23299 [MEDIUM] Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 Bluetooth skb_queue_purge release of resource (WID-SEC-2026-0861)
A vulnerability was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 and classified as critical. Affected by this vulnerability is the function skb_queue_purge of the component Bluetooth. Executing a manipulation can lead to missing release of resource.
This vulnerability is handled as CVE-2026-23299. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-2286-mwvj-8983: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enab
ghsa_unreviewed·2026-03-25
CVE-2026-23299 GHSA-2286-mwvj-8983: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enab
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
OSV
CVE-2026-23299: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enable
osv·2026-03-25
CVE-2026-23299 CVE-2026-23299: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enable
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, or if the controller is removed unexpectedly, these SKBs will leak. Fix by adding skb_queue_purge() calls for sk_error_queue in affected bluetooth destructors. RFCOMM does not currently use sk_error_queue.
OSV
Bluetooth: purge error queues in socket destructors
osv·2026-03-25
CVE-2026-23299 Bluetooth: purge error queues in socket destructors
Bluetooth: purge error queues in socket destructors
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23299 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23299 CVE-2026-23299 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23299 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
Source : NVD
Published March 25, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Prob
Bugzilla
CVE-2026-23299 kernel: Bluetooth: purge error queues in socket destructors
bugzilla·2026-03-25·CVSS 5.5
CVE-2026-23299 [MEDIUM] CVE-2026-23299 kernel: Bluetooth: purge error queues in socket destructors
CVE-2026-23299 kernel: Bluetooth: purge error queues in socket destructors
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: purge error queues in socket destructors
When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued
into sk_error_queue and will stay there until consumed. If userspace never
gets to read the timestamps, or if the controller is removed unexpectedly,
these SKBs will leak.
Fix by adding skb_queue_purge() calls for sk_error_queue in affected
bluetooth destructors. RFCOMM does not currently use sk_error_queue.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026032526-CVE-2026-23299-6471@gregkh/T
2026-03-25
Published