Linux kernel is core infrastructure; a fix affects many organizations across multiple industries.
CVE-2026-43051
Linux kernel HID: wacom_bt_irq out-of-bounds read on short Bluetooth reports.
Is CVE-2026-43051 being exploited?
Not confirmed. CVE-2026-43051 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.26% probability of exploitation in the next 30 days.
How severe is CVE-2026-43051?
CVE-2026-43051 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43051?
Yes. A fix has been recorded for CVE-2026-43051. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43051 affect?
CVE-2026-43051 affects Linux kernel (Bluetooth HID - Wacom). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43051?
Update to patched kernel version
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds read in wacom_intuos_bt_irq from crafted BT HID reports; may leak memory or crash the kernel.
Patch when possible
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < d0ae84b3c9f3ea1a564eb1b7612113ca9fe8aada
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < 5b5b9730111808410e404ceac2fabd32eef92fbd
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < fa8901cb1f0b2113a342db93bd5684b59fe99dcf
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < 8bd690ac1242332c73cba10dacdad6c6642bbb94
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < 41026bcc0fdf82605205c27935ef719cbc07193b
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < c8dc23c97680eebefde06da5858aaef1b37cf75d
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < 3d78386b144453c47e81bf62dc3601b757f02d99
- affected>= 78761ff9bc4e944e0b4e5df1e7eedcfdbb1a9a1a and < 2f1763f62909ccb6386ac50350fa0abbf5bb16a9
- affected3.3
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.