CVE-2026-43018
HIGHBluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
Title source: cnaDescription
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage.
References (6)
Core 6
Core References
Scores
CVSS v3
8.8
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (16)
Linux/Linux
< 5.17
Linux/Linux
5.17
Linux/Linux
6.1.168 - 6.1.*
Linux/Linux
6.12.81 - 6.12.*
Linux/Linux
6.18.22 - 6.18.*
Linux/Linux
6.19.12 - 6.19.*
Linux/Linux
6.6.134 - 6.6.*
Linux/Linux
7.0
Linux/Linux
95118dd4edfec950898a00180c6f998df0a6406d - 1d0bdbfe3e91c11f0a704c52443a9446a10d699c
Linux/Linux
95118dd4edfec950898a00180c6f998df0a6406d - 59eecf0ffde15670e6a5e10c47be67f73d843b20
... and 6 more
Published
May 01, 2026
Tracked Since
May 01, 2026