CVE-2026-43019: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup and field access must be covered by hdev lock in set_cig_params_sync, otherwise it's possible it is freed concurrently. Take hdev lock to prevent hci_conn from being deleted or modified concurrently. Just RCU lock is not suitable here, as we also want to avoid "tearing" in the configuration.

Affected products

  • Linux Linux Kernel: from 6.6, before 6.12.81 (fixed in 6.12.81); from 6.13, before 6.18.22 (fixed in 6.18.22); from 6.19, before 6.19.12 (fixed in 6.19.12); version 6.4.16 only; version 6.5.3 only; version 7.0 only

Published 2026-05-01. Last modified 2026-06-19.