CVE-2026-43021: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails When hci_cmd_sync_queue_once() returns with error, the destroy callback will not be called. Fix leaking references / memory on these failures.

Affected products

  • Linux Linux Kernel: from 6.19, before 6.19.12 (fixed in 6.19.12); version 7.0 only

Published 2026-05-01. Last modified 2026-06-17.