CVE-2025-39889
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39889 is a vulnerability discovered in the Linux kernel's Bluetooth l2cap subsystem, specifically related to encryption key size validation during incoming connections. The vulnerability was disclosed on September 24, 2025, and affects various Linux distributions and their kernel versions (NVD).

Technical details

The vulnerability stems from insufficient validation of encryption key sizes in the Bluetooth l2cap subsystem when handling incoming connections. This issue specifically affects the Security Mode 4 Level 4 implementation, where the system fails to properly verify encryption key sizes ranging from 1 to 15 bytes, while the security mode requires a 16-byte key size. The vulnerability has been assigned a CVSS v3 score of 7.0, indicating a moderate to high severity level (Red Hat Security).

Impact

The vulnerability could potentially allow an attacker to establish Bluetooth connections with weaker encryption than required by the security policy, potentially compromising the confidentiality and integrity of Bluetooth communications. This particularly affects systems implementing Security Mode 4 Level 4, which requires the highest level of Bluetooth security (NVD).

Mitigation and workarounds

Multiple Linux distributions have released patches to address this vulnerability. Ubuntu has marked this as 'Some fixes available' with 39 of 83 affected packages being patched. Red Hat Enterprise Linux and other major distributions have also issued fixes. The primary mitigation is to update to the latest kernel version that includes the security patch (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39886MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-core
NoYesSep 23, 2025
CVE-2025-39889N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules-partner
NoYesSep 24, 2025
CVE-2025-39888N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoNoSep 23, 2025
CVE-2025-39887N/AN/A
  • Linux KernelLinux Kernel
  • kernel-doc
NoNoSep 23, 2025
CVE-2025-39884N/AN/A
  • Linux KernelLinux Kernel
  • linux
NoYesSep 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management