Junglewise Threat Intelligence

CVE-2026-31773: Linux Kernel incorrect authentication in Bluetooth SMP

CVE-2026-31773 · Severity: high · CVSS 8.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth subsystem could allow an attacker to bypass security protections during the pairing process. Specifically, the system incorrectly labels certain encryption keys as 'authenticated' even when they were generated using a less secure method that does not protect against person-in-the-middle attacks. This could allow an attacker within Bluetooth range to intercept or manipulate sensitive data transmitted between paired devices.

Technical details

A vulnerability exists in the Bluetooth Security Manager Protocol (SMP) implementation within the Linux kernel's net/bluetooth/smp.c. The legacy responder path in smp_random() incorrectly labels the Short Term Key (STK) as authenticated based on the requested security level (BT_SECURITY_HIGH) rather than the actual MITM (Man-in-the-Middle) protection achieved during the pairing flow. In 'Just Works' or 'Confirm' legacy pairing modes, the SMP_FLAG_MITM_AUTH flag remains clear, yet the STK was being stored as authenticated. This mismatch in key metadata allows unauthenticated connections to bypass security requirements intended for authenticated links. The fix ensures the STK authentication status is derived from the actual MITM state.

Affected products

  • Linux Linux Kernel 3.15.5 to 3.16, 5.11 to 5.15.203, 6.13 to 6.18.22, 5.16 to 6.1.168, 6.19 to 6.19.12, 6.7 to 6.12.81, 6.2 to 6.6.134, 3.16.1 to 5.10.253

Timeline

  • 2026-05-01: disclosed
  • 2026-05-01: advisory
  • 2026-04-11: patched: Patched in various stable branches including 6.18.22 and 6.19.12

References

Related threats