A flaw in the Linux kernel's Bluetooth management (MGMT) component, tracked as CVE-2026-43020, was fixed after maintainers found that Long Term Key (LTK) enc_size values were not properly validated during load operations. An attacker with local low-privilege access could supply an enc_size larger than the 16-byte key buffer, allowing invalid data to be stored and later used in fixed-size stack operations when the kernel replied to LE LTK requests, creating a stack buffer overflow condition with denial-of-service and possible broader memory-corruption impact.
The vulnerable code is in net/bluetooth/mgmt.c and has reportedly been present since Linux kernel 3.4. Upstream fixes were released across multiple stable branches, including 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, and 7.0, by rejecting oversized enc_size values during management LTK record validation. Red Hat said fixes were issued for Red Hat Enterprise Linux 8, 9, and 10 through RHSA advisories, while RHEL 7, RHEL 7 kernel-rt, and RHEL 9 kernel-rt remained listed as affected at publication; RHEL 6 was listed as not affected because the vulnerable code is absent.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On May 28, 2026, Red Hat last modified its CVE-2026-43020 record to reflect fixed products and remaining affected ones. The update listed RHEL 10 kernel, RHEL 8 kernel and kernel-rt, and RHEL 9 kernel as fixed, while RHEL 7 kernel, RHEL 7 kernel-rt, and RHEL 9 kernel-rt remained affected.
On May 28, 2026, Red Hat released fixes for CVE-2026-43020 in Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 kernel, and Red Hat Enterprise Linux 8 kernel and kernel-rt. The fixes were shipped in advisories RHSA-2026:21557, RHSA-2026:21556, RHSA-2026:21706, and RHSA-2026:21745.
Red Hat published its CVE-2026-43020 entry on May 1, 2026, classifying the Linux kernel Bluetooth MGMT issue as Moderate severity and describing local low-privilege exploitation that could cause denial of service or broader memory corruption.
The kernel advisory reported that CVE-2026-43020 was fixed in stable releases 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, and 7.0. These releases incorporated the validation change preventing oversized LTK enc_size values from reaching stored key state.
On May 1, 2026, the Linux kernel CVE team announced CVE-2026-43020 for a Bluetooth MGMT vulnerability caused by improper validation of LTK enc_size values. The advisory said the flaw was fixed by rejecting oversized enc_size values during management LTK record validation.
The vulnerable Bluetooth management code path for loading Long Term Keys was introduced in Linux kernel version 3.4, allowing an oversized LTK enc_size value to later drive fixed-size stack operations and create a stack buffer overflow condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.