PT-2026-36437 · Linux · Linux

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-43020

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate LTK enc size on load
Load Long Term Keys stores the user-provided enc size and later uses it to size fixed-size stack operations when replying to LE LTK requests. An enc size larger than the 16-byte key buffer can therefore overflow the reply stack buffer.
Reject oversized enc size values while validating the management LTK record so invalid keys never reach the stored key state.

Related Identifiers

CVE-2026-43020

Affected Products

Linux