SEPTEMBER 26, 2026
Live Feed
Back to database
Case File

CVE-2026-43019

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Linux.

CVE
CVE-2026-43019
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup and field access must be covered by hdev lock in set_cig_params_sync, otherwise it's possible it is freed concurrently. Take hdev lock to prevent hci_conn from being deleted or modified concurrently. Just RCU lock is not suitable here, as we also want to avoid "tearing" in the configuration.

Related CVEs

Other vulnerabilities affecting the same vendor(s)