CVE-2026-43022: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.
Affected products
- Linux Linux Kernel: from 6.9, before 6.19.12 (fixed in 6.19.12); version 6.1.120 only; version 6.6.51 only; version 6.8.9 only; version 7.0 only
Published 2026-05-01. Last modified 2026-06-17.