Junglewise Threat Intelligence

CVE-2026-43019: Linux Kernel use after free in Bluetooth hci_conn

CVE-2026-43019 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth subsystem could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system handles Bluetooth connection parameters without proper locking, leading to a memory error. This affects devices running various versions of the Linux operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel Bluetooth subsystem within the 'set_cig_params_sync' function in 'net/bluetooth/hci_conn.c'. The root cause is a lack of proper synchronization; 'hci_conn' lookups and field accesses were not protected by the 'hdev' lock, allowing the connection object to be freed concurrently by another process. A local attacker can exploit this race condition to trigger a kernel panic or achieve arbitrary code execution. The fix involves wrapping the lookup and configuration logic with 'hci_dev_lock' to ensure atomicity and prevent concurrent modification or deletion.

Affected products

  • Linux Linux Kernel 6.4.16 to 6.5, 6.5.3 to 6.6, 6.6 to 6.12.81, 6.18.22, 6.19.12

Timeline

  • 2026-05-01: disclosed: Initial publication date
  • 2026-04-11: patched: Patches applied to stable branches

References

Related threats