Improper input validation in Linux kernel - CVE-2026-43134
Published: May 7, 2026
Vulnerability identifier: #VU130608
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-43134
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass an encryption key size check.
The vulnerability exists due to improper input validation in the L2CAP LE connection request handling when processing L2CAP_LE_CONN_REQ packets. A remote attacker can send a specially crafted L2CAP_LE_CONN_REQ packet to bypass an encryption key size check.
How to mitigate CVE-2026-43134
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/138d7eca445ef37a0333425d269ee59900ca1104
- https://git.kernel.org/stable/c/335071c0c3637064ec250481f589075db44fe4e6
- https://git.kernel.org/stable/c/481ea39b342c347b6ac029f3d418486280be4e45
- https://git.kernel.org/stable/c/8dd43f9a9323f9c01bc8246da8d81a4c783c9e97
- https://git.kernel.org/stable/c/9118601ff90b79e8df3c0c98f48ae00c1b02ecef
- https://git.kernel.org/stable/c/96581749c7c14fbec32c35728520867929600041
- https://git.kernel.org/stable/c/ec91078e132179b04e0c3906b599816c056ceaad
- https://git.kernel.org/stable/c/fa6ad76fa8623c0a50d529cd5726fa5d819a3be4