CVE-2025-38118: Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
Bluetooth: MGMT: Fix UAF on mgmtremoveadvmonitorcomplete
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.96.1-1 - Upgrade
Upgrade
Linux kernel Bluetooth MGMT (net/bluetooth/mgmt.c)to a version that resolves this vulnerability.Fixed in 6.15.0-syzkaller-10402-g4cb6c8af8591
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38118?
CVE-2025-38118 is classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2025-38118?
To fix CVE-2025-38118, update your Linux kernel to a version that includes the patch addressing this vulnerability.
What impact does CVE-2025-38118 have on Linux systems?
CVE-2025-38118 can lead to use-after-free conditions, potentially causing crashes and instability in Linux systems.
Which versions of the Linux kernel are affected by CVE-2025-38118?
CVE-2025-38118 affects Linux kernel versions prior to 6.15.0.
Is CVE-2025-38118 a remote exploit vulnerability?
CVE-2025-38118 does not appear to be directly exploitable remotely; its impact is more relevant to local system users.