Race condition in Linux kernel - CVE-2026-43119
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a data race in hdev->req_status handling in the Bluetooth hci_sync subsystem when processing concurrent command synchronization operations across workqueues and event completion paths. A local user can trigger concurrent operations to cause a denial of service.
The issue arises because accesses occur from different workqueues and completion or abort paths that can run concurrently on different CPUs.