cbcvebase.
CVE-2026-43020
published 2026-05-01

CVE-2026-43020: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided enc_size and later uses it to size fixed-size stack operations when replying to LE LTK requests. An enc_size larger than the 16-byte key buffer can therefore overflow the reply stack buffer. Reject oversized enc_size values while validating the management LTK record so invalid keys never reach the stored key state.

Affected

18 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 0f37d1e65c6d71ad94ccfb5c602163c525db789d0f37d1e65c6d71ad94ccfb5c602163c525db789d
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 257cdb960d8ff6d60bb6461b03c814b6cf0c9e64257cdb960d8ff6d60bb6461b03c814b6cf0c9e64
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < c34577f517b556fb6ca173d45bf7e766ae2564cec34577f517b556fb6ca173d45bf7e766ae2564ce
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < f71695e81f4cb428f3c7e2138eae88199005b52cf71695e81f4cb428f3c7e2138eae88199005b52c
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 82f342b3b006ca1d65f4890c05f2ec32fcb808b682f342b3b006ca1d65f4890c05f2ec32fcb808b6
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 50fb64defa72a3fecd0af1ca7c6b47b5c5c2b25750fb64defa72a3fecd0af1ca7c6b47b5c5c2b257
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < 40ba329e8b4cd2fb11b0caf5e6a543ceaebb600940ba329e8b4cd2fb11b0caf5e6a543ceaebb6009
linuxlinux>= 346af67b8d116f01ef696fd47959a55deb2db8b6 < b8dbe9648d69059cfe3a28917bfbf7e61efd7f15b8dbe9648d69059cfe3a28917bfbf7e61efd7f15
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 3.4 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1686.1.168
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.126.19.12
linuxlinux_kernel>= 6.2 < 6.6.1346.6.134
linuxlinux_kernel>= 6.7 < 6.12.816.12.81

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.