cbcvebase.
CVE-2025-39889
published 2025-09-24

CVE-2025-39889: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.09%
0.6th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the security key with size from 1 to 15 bytes while the Security Mode 4 Level 4 requests 16 bytes key size. Currently PTS fails with the following logs: - expected:Connection Response: Code: [3 (0x03)] Code Identifier: (lt)WildCard: Exists(gt) Length: [8 (0x0008)] Destination CID: (lt)WildCard: Exists(gt) Source CID: [64 (0x0040)] Result: [3 (0x0003)] Connection refused - Security block Status: (lt)WildCard: Exists(gt), but received:Connection Response: Code: [3 (0x03)] Code Identifier: [1 (0x01)] Length: [8 (0x0008)] Destination CID: [64 (0x0040)] Source CID: [64 (0x0040)] Result: [0 (0x0000)] Connection Successful Status: [0 (0x0000)] No further information available And HCI logs: HCI Event: Command Complete (0x0e) plen 7 Read Encryption Key Size (0x05|0x0008) ncmd 1 Status: Success (0x00) Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) Key size: 7 > ACL Data RX: Handle 14 flags 0x02 dlen 12 L2CAP: Connection Request (0x02) ident 1 len 4 PSM: 4097 (0x1001) Source CID: 64 < ACL Data TX: Handle 14 flags 0x00 dlen 16 L2CAP: Connection Response (0x03) ident 1 len 8 Destination CID: 64 Source CID: 64 Result: Connection successful (0x0000) Status: No further information available (0x0000)

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < 24b2cdfc16e9bd6ab3d03b8e01c590755bd3141f24b2cdfc16e9bd6ab3d03b8e01c590755bd3141f
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < c6d527bbd3d3896375079f5dbc8b7f96734a3ba5c6d527bbd3d3896375079f5dbc8b7f96734a3ba5
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < 9e3114958d87ea88383cbbf38c89e04b8ea1bce59e3114958d87ea88383cbbf38c89e04b8ea1bce5
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < d49798ecd26e0ee7995a7fc1e90ca5cd9b4402d6d49798ecd26e0ee7995a7fc1e90ca5cd9b4402d6
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < d4ca2fd218caafbf50e3343ba1260c6a23b5676ad4ca2fd218caafbf50e3343ba1260c6a23b5676a
linuxlinux>= 288c06973daae4637f25a0d1bdaf65fdbf8455f9 < 522e9ed157e3c21b4dd623c79967f72c21e45b78522e9ed157e3c21b4dd623c79967f72c21e45b78
linuxlinux>= 4f911a538e089cce808a15dc3277250f4f8daef9 < ed503d340a501e414114ddc614a3aae4f6e9eae2ed503d340a501e414114ddc614a3aae4f6e9eae2
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 6.13 < 6.14.46.14.4
linuxlinux_kernel>= 6.2 < 6.6.886.6.88
linuxlinux_kernel>= 6.7 < 6.12.256.12.25
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.