Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43022

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 5.5

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.

A flaw was found in the Bluetooth Host Controller Interface (HCI) synchronization component of the Linux kernel. The hci_cmd_sync_queue_once() function did not properly signal when a command was already queued, which could lead to resource leaks. An attacker could potentially exploit this to cause a Denial of Service by exhausting system resources.

Отчет

A Moderate flaw was found in the Bluetooth Host Controller Interface (HCI) synchronization component of the Linux kernel. This issue could allow a local attacker to cause a Denial of Service by exhausting system resources due to improper handling of queued commands. Exploitation requires local access to the system or specific Bluetooth capabilities.

Меры по смягчению последствий

To mitigate this issue, disable the Bluetooth service on affected systems if it is not required. This prevents the vulnerable code path from being exercised. To disable the Bluetooth service:

sudo systemctl stop bluetooth sudo systemctl disable bluetooth

Note that disabling the Bluetooth service will prevent all Bluetooth functionality on the system. A system reboot may be required for the changes to take full effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2464433kernel: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.

CVSS3: 5.5
nvd
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.

msrc
2 месяца назад

Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists

CVSS3: 5.5
debian
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: B ...

CVSS3: 5.5
github
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.

5.5 Medium

CVSS3