Security readout for executives and security teams
Plain-English summary
CVE-2026-43322 is a Linux kernel Bluetooth flaw involving a use-after-free condition. The CVE rates it high severity. The scoring indicates a nearby attacker could potentially impact confidentiality, integrity, and availability without user interaction. No public source provided confirms active exploitation.
Executive priority
Treat as a high-priority kernel maintenance item for Bluetooth-enabled Linux assets. It is not currently supported as actively exploited by the provided sources, but the impact rating and no-user-interaction scoring justify timely remediation.
Technical view
The issue is in Linux Bluetooth hci_sync, specifically le_read_features_complete. A Bluetooth hci_conn object can be freed before completion handling, leading to a KASAN-detected slab use-after-free. The CVE includes stable kernel fix references and CVSS 3.1 score 8.8 with adjacent-network attack vector.
Likely exposure
Systems running affected Linux kernels with Bluetooth/LE functionality enabled are the primary concern. The CVE record identifies Linux as affected and includes version entries around 6.19, 6.19.12, and 7.0. Distribution backports may change exposure, so validate against vendor kernel advisories.
Exploitation context
The CVSS vector is AV:A/AC:L/PR:N/UI:N, meaning exploitation is modeled from adjacent proximity, not the internet. The source bundle shows a syzkaller/KASAN crash trace, not real-world exploitation. KEV status is false in the provided data.
Researcher notes
Evidence is limited to the CVE description, CVSS vector, KASAN trace, and Linux stable commit references. The provided source data does not include exploit details, distribution package names, or a complete affected-version matrix. Avoid assuming internet-reachable exposure.
Mitigation direction
Apply a vendor kernel update that includes the referenced Linux stable fixes.
Prioritize laptops, gateways, IoT, and servers with Bluetooth enabled.
If patch timing is uncertain, follow your Linux distribution’s CVE guidance.
Review whether Bluetooth is business-required on exposed systems.
Validation and detection
Inventory Linux kernel versions and Bluetooth-capable assets.
Compare installed kernels with vendor advisories for CVE-2026-43322.
Confirm whether referenced stable commits are included or backported.
Check Bluetooth enablement status on prioritized systems.
Monitor CISA KEV and vendor bulletins for exploitation updates.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-43322 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.