CVE-2025-39889
Bluetooth: l2cap: Check encryption key size on incoming connection
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the security key with size from 1 to 15 bytes while the Security Mode 4 Level 4 requests 16 bytes key size. Currently PTS fails with the following logs: - expected:Connection Response: Code: [3 (0x03)] Code Identifier: (lt)WildCard: Exists(gt) Length: [8 (0x0008)] Destination CID: (lt)WildCard: Exists(gt) Source CID: [64 (0x0040)] Result: [3 (0x0003)] Connection refused - Security block Status: (lt)WildCard: Exists(gt), but received:Connection Response: Code: [3 (0x03)] Code Identifier: [1 (0x01)] Length: [8 (0x0008)] Destination CID: [64 (0x0040)] Source CID: [64 (0x0040)] Result: [0 (0x0000)] Connection Successful Status: [0 (0x0000)] No further information available And HCI logs: < HCI Command: Read Encrypti.. (0x05|0x0008) plen 2 Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) > HCI Event: Command Complete (0x0e) plen 7 Read Encryption Key Size (0x05|0x0008) ncmd 1 Status: Success (0x00) Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) Key size: 7 > ACL Data RX: Handle 14 flags 0x02 dlen 12 L2CAP: Connection Request (0x02) ident 1 len 4 PSM: 4097 (0x1001) Source CID: 64 < ACL Data TX: Handle 14 flags 0x00 dlen 16 L2CAP: Connection Response (0x03) ident 1 len 8 Destination CID: 64 Source CID: 64 Result: Connection successful (0x0000) Status: No further information available (0x0000)
INFO
Published Date :
Sept. 24, 2025, 11:15 a.m.
Last Modified :
Sept. 26, 2026, 12:10 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | MEDIUM | [email protected] | ||||
| CVSS 3.1 | MEDIUM | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | ||||
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel.
- Apply security patches for Bluetooth module.
- Reboot the system to apply changes.
- Verify encryption key size enforcement.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-39889.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-39889 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-39889
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-39889 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2025-39889 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Sep. 26, 2026
Action Type Old Value New Value Added Translation Title: la biblioteca CGM_NIST_Loader.dll en JT2Go, Teamcenter Visualization, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: Bluetooth: l2cap: Verificar el tamaño de la clave de cifrado en la conexión entrante Esto es necesario para aprobar el caso de prueba GAP/SEC/SEM/BI-04-C PTS: Modo de seguridad 4 Nivel 4, Respondedor - Tamaño de clave de cifrado no válido - 128 bits Esto prueba la clave de seguridad con un tamaño de 1 a 15 bytes, mientras que el Modo de seguridad 4 Nivel 4 solicita un tamaño de clave de 16 bytes. Actualmente, PTS falla con los siguientes registros: - esperado:Respuesta de conexión: Código: [3 (0x03)] Código Identificador: (lt)WildCard: Exists(gt) Longitud: [8 (0x0008)] CID de destino: (lt)WildCard: Exists(gt) CID de origen: [64 (0x0040)] Resultado: [3 (0x0003)] Conexión rechazada - Bloqueo de seguridad Estado: (lt)WildCard: Exists(gt), pero recibido:Respuesta de conexión: Código: [3 (0x03)] Código Identificador: [1 (0x01)] Longitud: [8 (0x0008)] CID de destino: [64 (0x0040)] CID de origen: [64 (0x0040)] Resultado: [0 (0x0000)] Conexión exitosa Estado: [0 (0x0000)] No hay más información disponible Y registros HCI: < Comando HCI: Leer Cifrado.. (0x05|0x0008) plen 2 Handle: 14 Dirección: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) > Evento HCI: Comando Completado (0x0e) plen 7 Leer Tamaño de Clave de Cifrado (0x05|0x0008) ncmd 1 Estado: Éxito (0x00) Handle: 14 Dirección: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) Tamaño de clave: 7 > Datos ACL RX: Handle 14 flags 0x02 dlen 12 L2CAP: Solicitud de conexión (0x02) ident 1 len 4 PSM: 4097 (0x1001) CID de origen: 64 < Datos ACL TX: Handle 14 flags 0x00 dlen 16 L2CAP: Respuesta de conexión (0x03) ident 1 len 8 CID de destino: 64 CID de origen: 64 Resultado: Conexión exitosa (0x0000) Estado: No hay más información disponible (0x0000) -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4f911a538e089cce808a15dc3277250f4f8daef9', 'lessThan': 'ed503d340a501e414114ddc614a3aae4f6e9eae2', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': '24b2cdfc16e9bd6ab3d03b8e01c590755bd3141f', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': 'c6d527bbd3d3896375079f5dbc8b7f96734a3ba5', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': '9e3114958d87ea88383cbbf38c89e04b8ea1bce5', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': 'd49798ecd26e0ee7995a7fc1e90ca5cd9b4402d6', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': 'd4ca2fd218caafbf50e3343ba1260c6a23b5676a', 'versionType': 'git'}, {'status': 'affected', 'version': '288c06973daae4637f25a0d1bdaf65fdbf8455f9', 'lessThan': '522e9ed157e3c21b4dd623c79967f72c21e45b78', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/l2cap_core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.181', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.135', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.88', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.25', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.14.4', 'versionType': 'semver', 'lessThanOrEqual': '6.14.*'}, {'status': 'unaffected', 'version': '6.15', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/l2cap_core.c'], 'defaultStatus': 'affected'}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2025-39889', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-01-14T17:37:06.505788Z'} -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Apr. 02, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Mar. 04, 2026
Action Type Old Value New Value Added Reference https://git.kernel.org/stable/c/ed503d340a501e414114ddc614a3aae4f6e9eae2 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jan. 14, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE CWE-326 -
Initial Analysis by [email protected]
Dec. 12, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE CWE-326 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.88 *cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.181 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.135 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.25 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.14.4 Added Reference Type kernel.org: https://git.kernel.org/stable/c/24b2cdfc16e9bd6ab3d03b8e01c590755bd3141f Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/522e9ed157e3c21b4dd623c79967f72c21e45b78 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/9e3114958d87ea88383cbbf38c89e04b8ea1bce5 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/c6d527bbd3d3896375079f5dbc8b7f96734a3ba5 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d49798ecd26e0ee7995a7fc1e90ca5cd9b4402d6 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d4ca2fd218caafbf50e3343ba1260c6a23b5676a Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 24, 2025
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the security key with size from 1 to 15 bytes while the Security Mode 4 Level 4 requests 16 bytes key size. Currently PTS fails with the following logs: - expected:Connection Response: Code: [3 (0x03)] Code Identifier: (lt)WildCard: Exists(gt) Length: [8 (0x0008)] Destination CID: (lt)WildCard: Exists(gt) Source CID: [64 (0x0040)] Result: [3 (0x0003)] Connection refused - Security block Status: (lt)WildCard: Exists(gt), but received:Connection Response: Code: [3 (0x03)] Code Identifier: [1 (0x01)] Length: [8 (0x0008)] Destination CID: [64 (0x0040)] Source CID: [64 (0x0040)] Result: [0 (0x0000)] Connection Successful Status: [0 (0x0000)] No further information available And HCI logs: < HCI Command: Read Encrypti.. (0x05|0x0008) plen 2 Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) > HCI Event: Command Complete (0x0e) plen 7 Read Encryption Key Size (0x05|0x0008) ncmd 1 Status: Success (0x00) Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) Key size: 7 > ACL Data RX: Handle 14 flags 0x02 dlen 12 L2CAP: Connection Request (0x02) ident 1 len 4 PSM: 4097 (0x1001) Source CID: 64 < ACL Data TX: Handle 14 flags 0x00 dlen 16 L2CAP: Connection Response (0x03) ident 1 len 8 Destination CID: 64 Source CID: 64 Result: Connection successful (0x0000) Status: No further information available (0x0000) Added Reference https://git.kernel.org/stable/c/24b2cdfc16e9bd6ab3d03b8e01c590755bd3141f Added Reference https://git.kernel.org/stable/c/522e9ed157e3c21b4dd623c79967f72c21e45b78 Added Reference https://git.kernel.org/stable/c/9e3114958d87ea88383cbbf38c89e04b8ea1bce5 Added Reference https://git.kernel.org/stable/c/c6d527bbd3d3896375079f5dbc8b7f96734a3ba5 Added Reference https://git.kernel.org/stable/c/d49798ecd26e0ee7995a7fc1e90ca5cd9b4402d6 Added Reference https://git.kernel.org/stable/c/d4ca2fd218caafbf50e3343ba1260c6a23b5676a