CVE-2025-38117: Bluetooth: MGMT: Protect mgmt_pending list with its own lock
Bluetooth: MGMT: Protect mgmtpending list with its own lock
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38117?
CVE-2025-38117 is classified as a medium severity vulnerability due to potential crashes caused by improper concurrency handling.
How do I fix CVE-2025-38117?
To fix CVE-2025-38117, update to the latest version of the Linux kernel where the vulnerability has been patched.
What systems are affected by CVE-2025-38117?
CVE-2025-38117 affects the Linux kernel, specifically versions that utilize the Bluetooth management subsystem.
What types of exploits are possible with CVE-2025-38117?
Exploiting CVE-2025-38117 can lead to unexpected crashes of the Bluetooth subsystem in the affected Linux kernel.
Is CVE-2025-38117 present in older Linux kernel versions?
Yes, CVE-2025-38117 is present in older Linux kernel versions prior to the issuance of the corresponding patch.