LiveActive security incident?Get immediate response
CVE Record

CVE-2025-39889: Bluetooth: l2cap: Check encryption key size on incoming connection

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the security key with size from 1 to 15 bytes while the Security Mode 4 Level 4 requests 16 bytes key size. Currently PTS fails with the following logs: - expected:Connection Response: Code: [3 (0x03)] Code Identifier: (lt)WildCard: Exists(gt) Length: [8 (0x0008)] Destination CID: (lt)WildCard: Exists(gt) Source CID: [64 (0x0040)] Result: [3 (0x0003)] Connection refused - Security block Status: (lt)WildCard: Exists(gt), but received:Connection Response: Code: [3 (0x03)] Code Identifier: [1 (0x01)] Length: [8 (0x0008)] Destination CID: [64 (0x0040)] Source CID: [64 (0x0040)] Result: [0 (0x0000)] Connection Successful Status: [0 (0x0000)] No further information available And HCI logs: < HCI Command: Read Encrypti.. (0x05|0x0008) plen 2 Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) > HCI Event: Command Complete (0x0e) plen 7 Read Encryption Key Size (0x05|0x0008) ncmd 1 Status: Success (0x00) Handle: 14 Address: 00:1B:DC:F2:24:10 (Vencer Co., Ltd.) Key size: 7 > ACL Data RX: Handle 14 flags 0x02 dlen 12 L2CAP: Connection Request (0x02) ident 1 len 4 PSM: 4097 (0x1001) Source CID: 64 < ACL Data TX: Handle 14 flags 0x00 dlen 16 L2CAP: Connection Response (0x03) ident 1 len 8 Destination CID: 64 Source CID: 64 Result: Connection successful (0x0000) Status: No further information available (0x0000)

HighCVSS 8.1Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Linux systems using Bluetooth may accept an incoming L2CAP connection protected by an encryption key weaker than the required 16 bytes. A nearby unauthenticated attacker could potentially undermine confidentiality or integrity of Bluetooth communications. The issue does not indicate availability impact, and the supplied evidence does not establish real-world exploitation.

Executive priority

Treat as a high-priority endpoint and embedded-Linux update where Bluetooth is enabled, especially in public, shared, or physically accessible environments. It is less urgent for systems without usable Bluetooth. Confirm exposure promptly, then patch through supported vendor channels; current evidence does not justify an emergency response based on active exploitation.

Technical view

The Linux Bluetooth L2CAP responder failed to validate encryption-key size when Security Mode 4 Level 4 required a 16-byte key. Testing showed connections using shorter keys could succeed instead of being refused with a security-block response. CVSS 3.1 is 8.1: adjacent-network access, low complexity, no privileges or user interaction, with high confidentiality and integrity impact.

Likely exposure

Exposure is limited to Linux systems with affected kernels and relevant Bluetooth functionality enabled or reachable by nearby devices. The bundle identifies affected kernel releases beginning with 5.11 and lists several later branch versions, but does not provide complete range semantics. Distribution backports may change status, so kernel version alone is insufficient.

Exploitation context

The attacker must be within Bluetooth range, making this an adjacent-network rather than internet-scale threat. No privileges or user interaction are required according to the CVSS vector. The bundle states KEV is false and contains no evidence of active exploitation, public proof-of-concept availability, or observed attacks.

Researcher notes

The weakness maps to CWE-326: inadequate encryption strength. The observable defect is acceptance of an incoming L2CAP connection using a 1–15-byte key when 16 bytes are required. The supplied commit references indicate fixes across stable branches. Exact vulnerable ranges, distribution-specific backports, affected Bluetooth profiles, and practical attack outcomes are not fully established by the bundle.

Mitigation direction

  • Install a vendor-supported kernel containing the applicable upstream or stable fix.
  • Check distribution advisories because vendors may backport fixes without changing to the listed upstream version.
  • Disable Bluetooth where it is unnecessary until affected systems can be updated.
  • Prioritize exposed endpoints handling sensitive Bluetooth communications or operating in untrusted physical locations.

Validation and detection

  • Inventory Linux kernel versions and identify systems with Bluetooth hardware or services enabled.
  • Compare each distribution package against its vendor advisory and backport status.
  • Confirm the installed kernel includes the applicable referenced stable commit or vendor-equivalent fix.
  • After updating, verify short encryption keys are rejected when Security Mode 4 Level 4 is required.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-326: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-39889 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.1CVSS 3.1HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N2.85.2Linux
5.5CVSS 3.1MediumCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H1.83.6CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

8.1High
CVSS 3.1 vector shape for CVE-2025-39889Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux4f911a538e089cce808a15dc3277250f4f8daef9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9, 288c06973daae4637f25a0d1bdaf65fdbf8455f9unaffected
LinuxLinux5.11, 0, 5.15.181, 6.1.135, 6.6.88, 6.12.25, 6.14.4, 6.15affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-326 · source CWE mapping

Inadequate Encryption Strength

Inadequate Encryption Strength represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.