CVE-2026-43018

HIGH

Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (16)
Linux/Linux < 5.17
Linux/Linux 5.17
Linux/Linux 6.1.168 - 6.1.*
Linux/Linux 6.12.81 - 6.12.*
Linux/Linux 6.18.22 - 6.18.*
Linux/Linux 6.19.12 - 6.19.*
Linux/Linux 6.6.134 - 6.6.*
Linux/Linux 7.0
Linux/Linux 95118dd4edfec950898a00180c6f998df0a6406d - 1d0bdbfe3e91c11f0a704c52443a9446a10d699c
Linux/Linux 95118dd4edfec950898a00180c6f998df0a6406d - 59eecf0ffde15670e6a5e10c47be67f73d843b20
... and 6 more
Published May 01, 2026
Tracked Since May 01, 2026