8.8
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
hci_conn lookup and field access must be covered by hdev lock in
hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed
concurrently.
Extend the hci_dev_lock critical section to cover all conn usage.
Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
hci_conn lookup and field access must be covered by hdev lock in
hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed
concurrently.
Extend the hci_dev_lock critical section to cover all conn usage.
AI Analysis
Potential Use-After-Free vulnerability in the Bluetooth hci_event handling
Basic Information
ID
CVE-2026-43018
Source
Linux
Published
May 1, 2026 at 14:15
Modified
May 3, 2026 at 05:46
Affected Product
Vendor
Linux
Product
Linux
Version
95118dd4edfec950898a00180c6f998df0a6406d, 5.17
Affected Versions
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 5.17
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 95118dd4edfec950898a00180c6f998df0a6406d
Linux Linux 5.17
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Linux
Product
Linux Kernel
Version
95118dd4edfec950898a00180c6f998df0a6406d, 5.17
References
- git.kernel.org /stable/c/59eecf0ffde15670e6a5e10c47be67f73d843b20
- git.kernel.org /stable/c/5fb69e1eeea9d6cba80517e9f058b56b34bc3a81
- git.kernel.org /stable/c/7cadb03be37e761130edb153544fe0770a842b19
- git.kernel.org /stable/c/1d0bdbfe3e91c11f0a704c52443a9446a10d699c
- git.kernel.org /stable/c/ea3cd36d7382d5f8309df04c275d20df139ed42c
- git.kernel.org /stable/c/b255531b27da336571411248c2a72a350662bd09