In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
hci_conn lookup and field access must be covered by hdev lock in
set_cig_params_sync, otherwise it's possible it is freed concurrently.
Take hdev lock to prevent hci_conn from being deleted or modified
concurrently. Just RCU lock is not suitable here, as we also want to
avoid "tearing" in the configuration.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-01 15:16
Updated : 2026-06-19 13:16
NVD link : CVE-2026-43019
Mitre link : CVE-2026-43019
CVE.ORG link : CVE-2026-43019
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
