CVE-2026-31773

8.8

Linux · kernel

A flaw in the Linux kernel Bluetooth subsystem improperly labels legacy Short Term Keys as authenticated, allowing potential security bypasses.

Executive summary

A high-severity cryptographic flaw in the Linux kernel Bluetooth subsystem allows unauthenticated attackers within adjacent range to compromise session security by mislabeling legacy Short Term Keys.

Vulnerability

This issue involves an improper authentication validation flaw in the Bluetooth Security Manager Protocol implementation, where the legacy responder path incorrectly stores keys as authenticated based on requested security levels rather than actual pairing results, requiring no user interaction.

Business impact

A successful exploit could lead to unauthorized access, confidentiality breaches, and integrity violations of Bluetooth communications. Given the high CVSS score of 8.8, attackers in adjacency can bypass expected security controls, potentially compromising sensitive data transmitted over wireless links and risking broader internal network exposure.

Remediation

Immediate Action: Update the Linux kernel to the patched versions provided by the vendor, such as version 5.10.253, 5.15.203, 6.1.168, or later.

Proactive Monitoring: Monitor system logs for unusual Bluetooth pairing requests, connection drops, or anomalies in wireless network traffic.

Compensating Controls: Restrict physical and wireless proximity to sensitive Bluetooth-enabled assets where possible until kernel updates can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators must treat this high-severity vulnerability with urgency due to the potential for session compromise via adjacent network vectors. Apply the official kernel patches immediately to ensure cryptographic keys accurately reflect pairing results and maintain secure Bluetooth communications.

More Linux CVEs

Sources