CVE-2026-43020
published 2026-05-01CVE-2026-43020: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate LTK enc_size on load
Load Long Term Keys stores the user-provided enc_size and later uses
it to size fixed-size stack operations when replying to LE LTK
requests. An enc_size larger than the 16-byte key buffer can therefore
overflow the reply stack buffer.
Reject oversized enc_size values while validating the management LTK
record so invalid keys never reach the stored key state.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 0f37d1e65c6d71ad94ccfb5c602163c525db789d | 0f37d1e65c6d71ad94ccfb5c602163c525db789d |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 257cdb960d8ff6d60bb6461b03c814b6cf0c9e64 | 257cdb960d8ff6d60bb6461b03c814b6cf0c9e64 |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < c34577f517b556fb6ca173d45bf7e766ae2564ce | c34577f517b556fb6ca173d45bf7e766ae2564ce |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < f71695e81f4cb428f3c7e2138eae88199005b52c | f71695e81f4cb428f3c7e2138eae88199005b52c |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 82f342b3b006ca1d65f4890c05f2ec32fcb808b6 | 82f342b3b006ca1d65f4890c05f2ec32fcb808b6 |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 50fb64defa72a3fecd0af1ca7c6b47b5c5c2b257 | 50fb64defa72a3fecd0af1ca7c6b47b5c5c2b257 |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 40ba329e8b4cd2fb11b0caf5e6a543ceaebb6009 | 40ba329e8b4cd2fb11b0caf5e6a543ceaebb6009 |
| linux | linux | >= 346af67b8d116f01ef696fd47959a55deb2db8b6 < b8dbe9648d69059cfe3a28917bfbf7e61efd7f15 | b8dbe9648d69059cfe3a28917bfbf7e61efd7f15 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 3.4 < 5.10.253 | 5.10.253 |
| linux | linux_kernel | >= 5.11 < 5.15.203 | 5.15.203 |
| linux | linux_kernel | >= 5.16 < 6.1.168 | 6.1.168 |
| linux | linux_kernel | >= 6.13 < 6.18.22 | 6.18.22 |
| linux | linux_kernel | >= 6.19 < 6.19.12 | 6.19.12 |
| linux | linux_kernel | >= 6.2 < 6.6.134 | 6.6.134 |
| linux | linux_kernel | >= 6.7 < 6.12.81 | 6.12.81 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Bluetooth: MGMT: validate LTK enc_size on load
vendor_redhat·2026-05-01·CVSS 7.0
CVE-2026-43020 [HIGH] CWE-120 kernel: Bluetooth: MGMT: validate LTK enc_size on load
kernel: Bluetooth: MGMT: validate LTK enc_size on load
A flaw was found in the Linux kernel's Bluetooth management (MGMT) component. An attacker could exploit a vulnerability in how Long Term Keys (LTK) are loaded. By providing an oversized encryption size, a stack buffer overflow can occur, potentially leading to a denial of service.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - A
GHSA
GHSA-4qqh-3j35-gpcq: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate LTK enc_size on load
Load Long Term Keys stores the us
ghsa_unreviewed·2026-05-01
CVE-2026-43020 GHSA-4qqh-3j35-gpcq: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate LTK enc_size on load
Load Long Term Keys stores the us
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate LTK enc_size on load
Load Long Term Keys stores the user-provided enc_size and later uses
it to size fixed-size stack operations when replying to LE LTK
requests. An enc_size larger than the 16-byte key buffer can therefore
overflow the reply stack buffer.
Reject oversized enc_size values while validating the management LTK
record so invalid keys never reach the stored key state.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0f37d1e65c6d71ad94ccfb5c602163c525db789dhttps://git.kernel.org/stable/c/257cdb960d8ff6d60bb6461b03c814b6cf0c9e64https://git.kernel.org/stable/c/40ba329e8b4cd2fb11b0caf5e6a543ceaebb6009https://git.kernel.org/stable/c/50fb64defa72a3fecd0af1ca7c6b47b5c5c2b257https://git.kernel.org/stable/c/82f342b3b006ca1d65f4890c05f2ec32fcb808b6https://git.kernel.org/stable/c/b8dbe9648d69059cfe3a28917bfbf7e61efd7f15https://git.kernel.org/stable/c/c34577f517b556fb6ca173d45bf7e766ae2564cehttps://git.kernel.org/stable/c/f71695e81f4cb428f3c7e2138eae88199005b52c
2026-05-01
Published