CVE-2026-23299Disclosure(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, or if the controller is removed unexpectedly, these SKBs will leak. Fix by adding skb_queue_purge() calls for sk_error_queue in affected bluetooth destructors. RFCOMM does not currently use sk_error_queue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-772

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-28: 1Mentions · 2026-05-29: 1Technical Details · 2026-03-25: 2Technical Details · 2026-05-29: 103-2503-2805-29
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure2
2026-03-281
General1
2026-05-291
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23299 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMES… https://www.cve.org/CVERecord?id=CVE-2026-23299

    Post summary

    CVE‑2026‑23299 is a resolved Bluetooth socket destructor issue in the Linux kernel, described with limited technical specifics and no evidence of active exploitation or granted patch details.

    00010220
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 #Linux Kernel Bluetooth Vulnerability, #CVE-2026-23299 (Medium) -DC-May2026-50 https://dailycve.com/linux-kernel-bluetooth-vulnerability-cve-2026-23299-medium-dc-may2026-50/

    Post summary

    The post announces a medium‑severity Linux kernel Bluetooth vulnerability (CVE‑2026‑23299) with a link to more details on DailyCVE, but provides no PoC, exploit, or patch information.

    0000053
    207 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23299 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23299 #CVE-2026-23299 #CVE   #CyberSecurity #InfoSec https://t.co/UHQdtCo748

    Post summary

    The tweet alerts users to a newly disclosed CVE but offers no details about exploitation, impact, or remediation.

    0000026
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23299 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMES… https://www.cve.org/CVERecord?id=CVE-2026-23299 ----- Traducción: CVE-2026-23299 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑23299, a Linux kernel Bluetooth issue that has been resolved, provides a brief technical summary, but offers no PoC, exploit, or patch details.

    0000038
    61 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more