Home

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-06 | Updated 2026-05-08 | Assigner Linux




HIGH: 8.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Product status

Default status
unaffected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 335071c0c3637064ec250481f589075db44fe4e6
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before fa6ad76fa8623c0a50d529cd5726fa5d819a3be4
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 9118601ff90b79e8df3c0c98f48ae00c1b02ecef
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 481ea39b342c347b6ac029f3d418486280be4e45
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before ec91078e132179b04e0c3906b599816c056ceaad
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 96581749c7c14fbec32c35728520867929600041
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 8dd43f9a9323f9c01bc8246da8d81a4c783c9e97
affected

27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d (git) before 138d7eca445ef37a0333425d269ee59900ca1104
affected

Default status
affected

3.14
affected

Any version before 3.14
unaffected

5.10.252 (semver)
unaffected

5.15.202 (semver)
unaffected

6.1.165 (semver)
unaffected

6.6.128 (semver)
unaffected

6.12.75 (semver)
unaffected

6.18.16 (semver)
unaffected

6.19.6 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/335071c0c3637064ec250481f589075db44fe4e6

git.kernel.org/...c/fa6ad76fa8623c0a50d529cd5726fa5d819a3be4

git.kernel.org/...c/9118601ff90b79e8df3c0c98f48ae00c1b02ecef

git.kernel.org/...c/481ea39b342c347b6ac029f3d418486280be4e45

git.kernel.org/...c/ec91078e132179b04e0c3906b599816c056ceaad

git.kernel.org/...c/96581749c7c14fbec32c35728520867929600041

git.kernel.org/...c/8dd43f9a9323f9c01bc8246da8d81a4c783c9e97

git.kernel.org/...c/138d7eca445ef37a0333425d269ee59900ca1104

cve.org (CVE-2026-43134)

nvd.nist.gov (CVE-2026-43134)

Download JSON