CVE-2026-43134

Source
https://cve.org/CVERecord?id=CVE-2026-43134
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43134.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43134
Downstream
Published
2026-05-06T11:27:21.541Z
Modified
2026-05-28T03:53:28.943825536Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix missing key size check for L2CAPLECONN_REQ

This adds a check for encryption key size upon receiving L2CAPLECONNREQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAPCRLEBADKEYSIZE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43134.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
27e2d4c8d28be1d1b4ecfbffab572d7dbd35254d
Fixed
335071c0c3637064ec250481f589075db44fe4e6
Fixed
fa6ad76fa8623c0a50d529cd5726fa5d819a3be4
Fixed
9118601ff90b79e8df3c0c98f48ae00c1b02ecef
Fixed
481ea39b342c347b6ac029f3d418486280be4e45
Fixed
ec91078e132179b04e0c3906b599816c056ceaad
Fixed
96581749c7c14fbec32c35728520867929600041
Fixed
8dd43f9a9323f9c01bc8246da8d81a4c783c9e97
Fixed
138d7eca445ef37a0333425d269ee59900ca1104

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43134.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
5.10.252
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.202
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.165
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.128
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.75
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43134.json"