PT-2026-36434 · Linux · Linux Kernel
Published
2026-04-01
·
Updated
2026-05-15
·
CVE-2026-43017
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Bluetooth MGMT component where the
mesh send() function fails to verify that the bytes provided for the flexible adv data[] array match the embedded adv data len field. Because MGMT MESH SEND SIZE only covers the fixed header, a truncated command can bypass the 20 to 50 byte range check, potentially causing the asynchronous mesh send path to read past the end of the queued command buffer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel