PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43059 Linux CVE debrief

CVE-2026-43059 is a Linux kernel Bluetooth MGMT memory-safety issue in command completion handling. The flaw can corrupt kernel lists or free pending commands incorrectly, creating a risk of kernel panic and use-after-free conditions.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-05-06
Advisory published
2026-05-05
Advisory updated
2026-05-06

Who should care

Linux kernel maintainers, distribution security teams, and operators running kernels with Bluetooth MGMT support should prioritize this issue, especially on systems where Bluetooth management features are enabled or customized.

Technical summary

The root cause is a semantic change introduced by mgmt_pending_valid(): it validates a pending command and also unlinks it from the pending list when valid. In mgmt_add_adv_patterns_monitor_complete(), the success path still called mgmt_pending_remove(), which can double-remove the same list entry and corrupt the list. In set_mesh_complete(), an error-path mgmt_pending_foreach() remained even though the current command had already been unlinked; that loop could target other pending mesh commands and free them while still in use, creating a use-after-free risk. The patch also simplifies mgmt_cmd_status() to use cmd->opcode directly.

Defensive priority

High

Recommended defensive actions

  • Apply Linux kernel updates that include the referenced fixes for Bluetooth MGMT completion handlers.
  • If you maintain a downstream or custom kernel, backport the relevant stable commits referenced in the advisory and verify the Bluetooth MGMT code paths.
  • Prioritize patching systems that rely on Bluetooth management features, including embedded and fleet devices.
  • Watch for kernel crashes, list corruption symptoms, or unexpected Bluetooth management instability until patched builds are deployed.
  • Confirm that your distribution’s backport includes both the list-corruption fix in mgmt_add_adv_patterns_monitor_complete() and the UAF fix in set_mesh_complete().

Evidence notes

This debrief is based on the supplied CVE description and NVD record metadata. The issue is described as resolved in Linux kernel Bluetooth MGMT command complete handlers, with references to four stable kernel commits. No CVSS vector or severity was provided in the source corpus, so no score is stated here.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43059 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43059

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43059 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43059

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/02023ff760cc104a5d86a82ef5b8dd89098ad78d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/17f89341cb4281d1da0e2fb0de5406ab7c4e25ef

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/695b45b2262fcb5e71bed1175aad59c72f92aa78

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b5c5e96f3b0a5003c3ff98ebb33e59afec51dd77

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.