PatchSiren cyber security CVE debrief
CVE-2026-43059 Linux CVE debrief
CVE-2026-43059 is a Linux kernel Bluetooth MGMT memory-safety issue in command completion handling. The flaw can corrupt kernel lists or free pending commands incorrectly, creating a risk of kernel panic and use-after-free conditions.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-05
- Original CVE updated
- 2026-05-06
- Advisory published
- 2026-05-05
- Advisory updated
- 2026-05-06
Who should care
Linux kernel maintainers, distribution security teams, and operators running kernels with Bluetooth MGMT support should prioritize this issue, especially on systems where Bluetooth management features are enabled or customized.
Technical summary
The root cause is a semantic change introduced by mgmt_pending_valid(): it validates a pending command and also unlinks it from the pending list when valid. In mgmt_add_adv_patterns_monitor_complete(), the success path still called mgmt_pending_remove(), which can double-remove the same list entry and corrupt the list. In set_mesh_complete(), an error-path mgmt_pending_foreach() remained even though the current command had already been unlinked; that loop could target other pending mesh commands and free them while still in use, creating a use-after-free risk. The patch also simplifies mgmt_cmd_status() to use cmd->opcode directly.
Defensive priority
High
Recommended defensive actions
- Apply Linux kernel updates that include the referenced fixes for Bluetooth MGMT completion handlers.
- If you maintain a downstream or custom kernel, backport the relevant stable commits referenced in the advisory and verify the Bluetooth MGMT code paths.
- Prioritize patching systems that rely on Bluetooth management features, including embedded and fleet devices.
- Watch for kernel crashes, list corruption symptoms, or unexpected Bluetooth management instability until patched builds are deployed.
- Confirm that your distribution’s backport includes both the list-corruption fix in mgmt_add_adv_patterns_monitor_complete() and the UAF fix in set_mesh_complete().
Evidence notes
This debrief is based on the supplied CVE description and NVD record metadata. The issue is described as resolved in Linux kernel Bluetooth MGMT command complete handlers, with references to four stable kernel commits. No CVSS vector or severity was provided in the source corpus, so no score is stated here.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43059 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43059
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43059 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43059
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/02023ff760cc104a5d86a82ef5b8dd89098ad78d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/17f89341cb4281d1da0e2fb0de5406ab7c4e25ef
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/695b45b2262fcb5e71bed1175aad59c72f92aa78
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b5c5e96f3b0a5003c3ff98ebb33e59afec51dd77
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.