1sealsemantic last-mile verification

Research / Finding

Linux Bluetooth: pairing without MITM protection

F-TORVALDS-LINUX-BT-SMP-001

Read the full technical write-up →

Root cause, affected code and disclosure timeline.

At a glance

Conditions
Legacy Bluetooth pairing can satisfy BT_SECURITY_HIGH without authenticated MITM protection.
What to do
Check your kernel vendor's backports for both linked commits. A mainline fix does not establish the state of your distribution.

1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.

Fix and severity by source
  • CVE-2026-43334 (upstream record)Source observed: 2026-09-23

    Fix / version: Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7
    Severity: 8.8 / 10; CVSS 3.1

  • CVE-2026-31773 (upstream record)Source observed: 2026-09-23

    Fix / version: Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe
    Severity: 8.8 / 10; CVSS 3.1

  • 1SEAL-2026-011 (1seal assessment)Write-up dated: 2026-04-04

    Fix / version: mainline commits d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7 and 20756fec2f0108cb88e815941f1ffff88dc286fe
    Severity: 7.1 / 10; CVSS 3.1

Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.

Bluetooth SMP legacy pairing satisfies BT_SECURITY_HIGH without MITM protection: the flag asserts a property the transport does not have.

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

8.8high
CVE-2026-43334CVEtorvalds/linux

Bluetooth: SMP: force responder MITM requirements before building the pairing response

Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7

patched
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
CVE
CVE-2026-43334
Status
patched
Fixed in
Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7
Recorded credit
Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.
Disclosure date
Note
CNA record verified PUBLISHED on 2026-09-23 and matched to the exact mainline fix. Upstream authorship source: https://github.com/torvalds/linux/commit/d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7. Score is the current Linux CNA CVSS v3.1, not a revision of the original report assessment.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE registry state
PUBLISHED
CVE state checked

F-TORVALDS-LINUX-BT-SMP-001: Verification failures. Pairing security state asserts MITM protection without establishing it. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-BT-SMP-001

Security area (1seal assessment): Identity. Bluetooth pairing can assert authenticated MITM protection without establishing it; this is a peer-authentication property. Reviewed 24 Sep 2026.

8.8high
CVE-2026-31773CVEtorvalds/linux

Bluetooth: SMP: derive legacy responder STK authentication from MITM state

Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe

patched
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
CVE
CVE-2026-31773
Status
patched
Fixed in
Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe
Recorded credit
Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.
Disclosure date
Note
CNA record verified PUBLISHED on 2026-09-23 and matched to the exact mainline fix. Upstream authorship source: https://github.com/torvalds/linux/commit/20756fec2f0108cb88e815941f1ffff88dc286fe. Score is the current Linux CNA CVSS v3.1, not a revision of the original report assessment.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE registry state
PUBLISHED
CVE state checked

F-TORVALDS-LINUX-BT-SMP-001: Verification failures. Pairing security state asserts MITM protection without establishing it. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-BT-SMP-001

Security area (1seal assessment): Identity. The legacy STK authentication flag must reflect the actual MITM state, not merely the requested protection level. Reviewed 24 Sep 2026.

7.1high
1SEAL-2026-0111SEAL advisorytorvalds/linux

Linux Bluetooth SMP legacy pairing can satisfy BT_SECURITY_HIGH without MITM

Fixed in: mainline commits d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7 and 20756fec2f0108cb88e815941f1ffff88dc286fe

Fix recordednot counted
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
CVE
CVE-2026-43334 / CVE-2026-31773
Status
patched
CWE
CWE-287
Fixed in
mainline commits d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7 and 20756fec2f0108cb88e815941f1ffff88dc286fe
Disclosure date
Recorded severity
high
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

F-TORVALDS-LINUX-BT-SMP-001: Verification failures. Pairing security state asserts MITM protection without establishing it. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-BT-SMP-001

Security area (1seal assessment): Identity. Bluetooth pairing can assert authenticated MITM protection without establishing it; this write-up describes the same peer-authentication gap. Reviewed 24 Sep 2026.

—score not recorded
torvalds/linuxReported fixtorvalds/linux

Bluetooth: SMP: force responder MITM requirements before building the pairing response

merged
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
CVE
CVE-2026-43334 / CVE-2026-31773
Status
merged
Reported via
bluetooth maintainers
Note
public mainline commits d05111bfe37b and 20756fec2f01 in torvalds/linux. the fix bundle aligns responder pairing policy and legacy STK authentication with actual MITM state. author is publicly listed as Oleh Konko <security@1seal.org> with Signed-off-by.

F-TORVALDS-LINUX-BT-SMP-001: Verification failures. Pairing security state asserts MITM protection without establishing it. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-BT-SMP-001

Security area (1seal assessment): Identity. Pairing security state asserts MITM protection without establishing it. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.