CVE-2026-23299: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, or if the controller is removed unexpectedly, these SKBs will leak. Fix by adding skb_queue_purge() calls for sk_error_queue in affected bluetooth destructors. RFCOMM does not currently use sk_error_queue.

Affected products

  • Linux Linux Kernel: from 6.15, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 7.0 only

Published 2026-03-25. Last modified 2026-06-17.