CVE-2026-43020

Source
https://cve.org/CVERecord?id=CVE-2026-43020
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43020.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43020
Downstream
Published
2026-05-01T14:15:23.699Z
Modified
2026-05-18T06:00:12.158765466Z
Summary
Bluetooth: MGMT: validate LTK enc_size on load
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: validate LTK enc_size on load

Load Long Term Keys stores the user-provided encsize and later uses it to size fixed-size stack operations when replying to LE LTK requests. An encsize larger than the 16-byte key buffer can therefore overflow the reply stack buffer.

Reject oversized enc_size values while validating the management LTK record so invalid keys never reach the stored key state.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43020.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
346af67b8d116f01ef696fd47959a55deb2db8b6
Fixed
0f37d1e65c6d71ad94ccfb5c602163c525db789d
Fixed
257cdb960d8ff6d60bb6461b03c814b6cf0c9e64
Fixed
c34577f517b556fb6ca173d45bf7e766ae2564ce
Fixed
f71695e81f4cb428f3c7e2138eae88199005b52c
Fixed
82f342b3b006ca1d65f4890c05f2ec32fcb808b6
Fixed
50fb64defa72a3fecd0af1ca7c6b47b5c5c2b257
Fixed
40ba329e8b4cd2fb11b0caf5e6a543ceaebb6009
Fixed
b8dbe9648d69059cfe3a28917bfbf7e61efd7f15

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43020.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.168
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.134
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.81
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43020.json"