CVE-2026-43334 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements before building the pairing response smp_cmd_pairing_req() currently builds the pairing response from the initiator auth_req before enforcing the local BT_SECURITY_HIGH requirement. If the initiator omits SMP_AUTH_MITM, the response can also omit it even though the local side still requires MITM. tk_request() then sees an auth value without SMP_AUTH_MITM and may select JUST_CFM, making method selection inconsistent with the pairing policy the responder already enforces. When the local side requires HIGH security, first verify that MITM can be achieved from the IO capabilities and then force SMP_AUTH_MITM in the response in both rsp.auth_req and auth. This keeps the responder auth bits and later method selection aligned.
A vulnerability in the Linux kernel's Bluetooth stack has been addressed, specifically within the Simple Pairing (SMP) protocol. The issue arose because the function that handles pairing requests built the response based on the initiator's authentication requirements before verifying the local security level. If the initiator did not include the Man-In-The-Middle (MITM) authentication, the response could also omit it, creating a mismatch with the local pairing policy that required high security. This inconsistency could lead to improper method selection during the pairing process. The vulnerability affected several versions of the Linux kernel.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/01bb4045d2306c266178f49ce0c3576d237a3040 | kernel.org | Patch |
| https://git.kernel.org/stable/c/425a22c5373d4e1b46492ab869074ebeeade61f3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7ab69426e7ecbd18a222ee2ec87ca612d30197d7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/91649c02c1baaa18cedf7fb425fa1f0f852c8183 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c8ff0ca6508535bccabd81c5c9dcc63de8a3d4fb | kernel.org | Patch |
| https://git.kernel.org/stable/c/d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ec17efb1ef91506cfd17a77692eaf4bbacb520ea | kernel.org | Patch |
| https://git.kernel.org/stable/c/fa14e0e19820b1bbdb42185c9c4efa950bcffef9 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.3, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | New CVE Received | kernel.org |