---
id: CVE-2026-90252
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: MGMT: free the HCI command when it is cancelled

  mgmt_hci_cmd_sync() queues the pending command with a NULL destroy
  callback, so it is only freed if send_hci…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: MGMT: free the HCI command when it is cancelled

  mgmt_hci_cmd_sync() queues the pending command with a NULL destroy
  callback, so it is only freed if send_hci…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f <
    e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93
  - >-
    Linux >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f <
    481533b03985177ddc805e0bd12fc07e7adf9040
  - >-
    Linux >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f <
    414b365ecea6c30357adee6b8a7c5edc03a03575
  - Linux 6.13
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:21.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90252'
references:
  - url: 'https://git.kernel.org/stable/c/414b365ecea6c30357adee6b8a7c5edc03a03575'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/481533b03985177ddc805e0bd12fc07e7adf9040'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e0cd7b34dc6b5414cac3d4cd376f73d3e9ffbd93'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.844Z'
epss: 0.00206
epssPercentile: 0.09446
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: free the HCI command when it is cancelled

mgmt_hci_cmd_sync() queues the pending command with a NULL destroy
callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled
entry is leaked, as _hci_cmd_sync_cancel_entry() does not release
entry->data when there is no destroy callback, and hci_cmd_sync_clear()
cancels every pending entry when the controller is unregistered. Nothing
else reclaims it either: mgmt_pending_new() does not put the command on
hdev->mgmt_pending.

The leak also pins the socket reference taken by mgmt_pending_new(), so
the mgmt socket is never released.

Free the command from a destroy callback. The now-empty done label is
replaced by a direct return.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
