HIGHCVE-2026-31511Published Modified CNA Linux
CVE-2026-31511: Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete This fixes the condition checking so mgmt_pending_valid is executed whenever status != -ECANCELED otherwise calling mgmt_pending_free(cmd) would kfree(cmd) without unlinking it from the list first, leaving a dangling pointer. Any subsequent list traversal (e.g., mgmt_pending_foreach during __mgmt_power_off, or another mgmt_pending_valid call) would dereference freed memory.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
02074dfffad76981ca451cb7fc98703d04ac562fe340666172cf747de58c283d2eef1f335f050538b3a89c33deffb3cb7877a7ea2e50734cd12b064f25f5fa4cd35f707344f65ce9e225b6528691dbbaa6.12.806.176.18.216.19.117.0bafec9325d4de26b6c49db75b5d5172de652aae0
Affected packages
- Linux / Linux< 2074dfffad76981ca451cb7fc98703d04ac562fe (from 0b60eb04b8524e1b4b3f07fea0d16fda9a677d9a) · < 340666172cf747de58c283d2eef1f335f050538b (from d71b98f253b079cbadc83266383f26fe7e9e103b) · < bafec9325d4de26b6c49db75b5d5172de652aae0 (from 302a1f674c00dd5581ab8e493ef44767c5101aab) · < 3a89c33deffb3cb7877a7ea2e50734cd12b064f2 (from 302a1f674c00dd5581ab8e493ef44767c5101aab) · < 5f5fa4cd35f707344f65ce9e225b6528691dbbaa (from 302a1f674c00dd5581ab8e493ef44767c5101aab) · 87a1f16f07c6c43771754075e08f45b41d237421
- Linux / Linux6.17Fixed in 0, 6.12.80, 6.18.21, 6.19.11, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H