PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23299 Linux kernel CVE debrief

A vulnerability in the Linux kernel's Bluetooth implementation could lead to SKB leaks when TX timestamping is enabled. The issue arises when SKBs are queued into sk_error_queue and remain there until consumed. If userspace fails to read the timestamps or the controller is unexpectedly removed, these SKBs will leak. The fix involves adding skb_queue_purge() calls for sk_error_queue in affected Bluetooth destructors.

Vendor
Linux kernel
Product
Linux kernel Bluetooth implementation
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-29
Advisory published
2026-03-25
Advisory updated
2026-05-29

Who should care

Linux system administrators and security teams should assess their exposure to this vulnerability and prioritize verifying the presence of the patches for the Linux kernel versions they are using.

Why it matters

A vulnerability in the Linux kernel's Bluetooth implementation could lead to SKB leaks when TX timestamping is enabled, requiring verification of patch presence and assessment of exposure.

  • Verify patch presence for Linux kernel versions in use.
  • Assess exposure to potential SKB leaks in Bluetooth implementation.
  • Monitor system logs for exploitation attempts.

Technical summary

The Linux kernel's Bluetooth implementation has a vulnerability that could lead to SKB leaks when TX timestamping is enabled. The issue arises when SKBs are queued into sk_error_queue and remain there until consumed. If userspace fails to read the timestamps or the controller is unexpectedly removed, these SKBs will leak. The fix involves adding skb_queue_purge() calls for sk_error_queue in affected Bluetooth destructors.

Defensive priority

Linux system administrators and security teams should prioritize verifying the presence of the patches for the Linux kernel versions they are using and assess their exposure to this vulnerability.

Recommended defensive actions

  • Verify the Linux kernel version and check if it is within the affected range.
  • Apply the available patches for the affected Linux kernel versions.
  • Monitor system logs for potential exploitation attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, its impact, and the affected Linux kernel versions. Patches are available for the affected versions. Linux system administrators and security teams should verify the presence of patches for the Linux kernel versions they are using and assess their exposure to this vulnerability. The fix involves adding skb_queue_purge() calls for sk_error_queue in affected Bluetooth destructors. Evidence limits suggest that defenders should verify patch presence and assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23299 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23299

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23299 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23299

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/21e4271e65094172aadd5beb8caea95dd0fbf6d7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2b6c942a526635f5c61d2f000258e620da32d3a7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3de7c10a950b36affc692d8bd2ac713852580e56

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.