CVE-2026-43018

Source
https://cve.org/CVERecord?id=CVE-2026-43018
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43018.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43018
Downstream
Published
2026-05-01T14:15:22.308Z
Modified
2026-05-18T06:00:12.010751671Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hcievent: fix potential UAF in hcileremoteconnparamreq_evt

hciconn lookup and field access must be covered by hdev lock in hcileremoteconnparamreq_evt, otherwise it's possible it is freed concurrently.

Extend the hcidevlock critical section to cover all conn usage.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43018.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
95118dd4edfec950898a00180c6f998df0a6406d
Fixed
59eecf0ffde15670e6a5e10c47be67f73d843b20
Fixed
5fb69e1eeea9d6cba80517e9f058b56b34bc3a81
Fixed
7cadb03be37e761130edb153544fe0770a842b19
Fixed
1d0bdbfe3e91c11f0a704c52443a9446a10d699c
Fixed
ea3cd36d7382d5f8309df04c275d20df139ed42c
Fixed
b255531b27da336571411248c2a72a350662bd09

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43018.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.168
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.134
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.81
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43018.json"