A moderate-severity Linux kernel vulnerability, tracked as CVE-2026-43051, was fixed in the Wacom HID driver after maintainers found that malformed Bluetooth HID reports could trigger an out-of-bounds read in wacom_intuos_bt_irq(). The bug affected handling of report IDs 0x03 and 0x04, where insufficient bounds checking allowed a malicious or compromised nearby Bluetooth device to send short reports that caused the kernel to read past the received buffer while copying data into the Wacom structure. The issue could lead to sensitive memory disclosure and system crashes.
The fix adds explicit length validation for the affected report types and warning logs when undersized reports are received, with upstream patches released across multiple stable kernel branches from 5.10.253 through 7.0. Red Hat said updates were issued for affected kernel packages in RHEL 8, 9, and 10, while some RHEL 7 and RHEL 9 kernel-rt variants remained affected at publication; RHEL 6 was not impacted because the vulnerable code was not present. Red Hat scored the flaw CVSS 7.1, while cve.org listed 8.1.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released a fix for CVE-2026-43051 in the Red Hat Enterprise Linux 8 kernel-rt package via advisory RHSA-2026:21745.
Red Hat released a fix for CVE-2026-43051 in the Red Hat Enterprise Linux 8 kernel via advisory RHSA-2026:21706.
Red Hat released a fix for CVE-2026-43051 in the Red Hat Enterprise Linux 10 kernel via advisory RHSA-2026:21557.
Red Hat released a fix for CVE-2026-43051 in the Red Hat Enterprise Linux 9 kernel via advisory RHSA-2026:21556.
Red Hat published its CVE entry for CVE-2026-43051, describing a moderate-severity out-of-bounds read in the Linux kernel Wacom HID driver that can be triggered by crafted short Bluetooth reports.
Fixes for CVE-2026-43051 were released in Linux kernel versions 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, and 7.0. The fix added explicit length checks for report IDs 0x03 and 0x04 and warning logs for short reports.
The Linux kernel CVE team assigned CVE-2026-43051 to an out-of-bounds read flaw in the Wacom HID driver’s wacom_intuos_bt_irq() function, caused by insufficient bounds checking on Bluetooth HID reports.
Red Hat last modified its CVE-2026-43051 entry, updating the vendor record for the Linux kernel Wacom HID vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.