CVE-2026-43021
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-43021 is a memory leak vulnerability in the Linux kernel's Bluetooth HCI synchronization subsystem. Specifically, when hci_cmd_sync_queue_once() returns an error, the destroy callback is not invoked, causing references and memory to leak. The vulnerability affects Linux kernel versions from 6.19 up to (but not including) 6.19.12, as well as 7.0 release candidates (rc1 through rc6). It was published on May 1, 2026, with patches released by May 8, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Github Advisory).

Technical details

The root cause is classified under CWE-772 (Missing Release of Resource after Effective Lifetime) and CWE-401 (Missing Release of Memory after Effective Lifetime), reflecting improper resource cleanup in the Bluetooth HCI command synchronization path. When hci_cmd_sync_queue_once() fails and returns an error code, the associated destroy callback is never called, leaving allocated memory and object references unreleased. Exploitation requires local access with low privileges, as an attacker must be able to trigger Bluetooth HCI command synchronization failures on the affected system. No public proof-of-concept exploit code is known to exist (Github Advisory).

Impact

Successful exploitation causes memory and reference leaks that accumulate over time within the kernel's Bluetooth HCI subsystem. A local low-privileged user can repeatedly trigger these failures, gradually exhausting system memory resources and degrading system performance. In severe cases, sustained exploitation could render the system unresponsive, constituting a denial-of-service condition. There is no impact on confidentiality or data integrity (Github Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (4th percentile), indicating a very low probability of exploitation in the near term. Exploitation is limited to local attackers with low-privilege access, further reducing the practical risk (Github Advisory).

Mitigation and workarounds

Update the Linux kernel to version 6.19.12 or later, which includes the fix for this vulnerability. For systems running 7.0 release candidates, the fix is included in the 7.0 stable release. Specific patches are available directly from the kernel stable tree at git.kernel.org. As an interim measure, restrict local system access to trusted users and monitor system memory usage for signs of gradual resource exhaustion in the Bluetooth subsystem (Github Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Fixed

sid

linux: 6.19.12-1

Fixed

trixie

linux

Fixed

Ubuntu

Fixed

bionic (esm-infra)

linux

Affected

bionic (fips-updates)

linux-fips

Affected

bionic (fips)

linux-fips

Affected

devel

linux

Not Affected

focal (esm-infra)

linux

Affected

focal (fips-updates)

linux-fips

Affected

focal (fips)

linux-fips

Affected

jammy

linux

Affected

RHEL / CentOS

Affected

RHEL 8

kernel-rt.src

Affected

RHEL 9

kernel-rt.src

Affected

RHEL 10

kernel.src

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management