Home

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup and field access must be covered by hdev lock in set_cig_params_sync, otherwise it's possible it is freed concurrently. Take hdev lock to prevent hci_conn from being deleted or modified concurrently. Just RCU lock is not suitable here, as we also want to avoid "tearing" in the configuration.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-01 | Updated 2026-05-03 | Assigner Linux




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

a091289218202bc09d9b9caa8afcde1018584aec (git) before 66d432e9b45bae7881ffcdb12cd8fd0bf254ef02
affected

a091289218202bc09d9b9caa8afcde1018584aec (git) before 7d568fede8eac91161a60b710aa920abe9b0fb9f
affected

a091289218202bc09d9b9caa8afcde1018584aec (git) before bad65b4b0a96139f023eadc28a33125963208449
affected

a091289218202bc09d9b9caa8afcde1018584aec (git) before a2639a7f0f5bf7d73f337f8f077c19415c62ed2c
affected

3a273cd0f47dd672d37736e623849374f9ab9ce9 (git)
affected

d8570c4c3f2a3e51b3c8b5e6ec898364c5c03062 (git)
affected

Default status
affected

6.6
affected

Any version before 6.6
unaffected

6.12.81 (semver)
unaffected

6.18.22 (semver)
unaffected

6.19.12 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/66d432e9b45bae7881ffcdb12cd8fd0bf254ef02

git.kernel.org/...c/7d568fede8eac91161a60b710aa920abe9b0fb9f

git.kernel.org/...c/bad65b4b0a96139f023eadc28a33125963208449

git.kernel.org/...c/a2639a7f0f5bf7d73f337f8f077c19415c62ed2c

cve.org (CVE-2026-43019)

nvd.nist.gov (CVE-2026-43019)

Download JSON