CVE-2025-38303: Bluetooth: eir: Fix possible crashes on eir_create_adv_data
Published Jul 10, 2025
·Updated
Bluetooth: eir: Fix possible crashes on eircreateadvdata
Affected Software
10 affected components
Linux Kernel
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.117.1-1
Microsoft azl3 kernel 6.6.104.2-4
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Linux Linux kernel>=5.16<6.12.34
Linux Linux kernel>=6.13<6.15.3
Linux Linux kernel=6.16-rc1
Microsoft azl3 kernel 6.6.119.3-1
Event History
Jul 10, 2025
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionSeverity
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·01:42 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:42 AM
Affected Software
Updated
via Microsoft·01:42 AM
SeverityAffected Software
Updated
via Microsoft·08:42 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38303?
CVE-2025-38303 has a high severity rating due to its potential to cause crashes in the Linux kernel's Bluetooth functionality.
2
How do I fix CVE-2025-38303?
To fix CVE-2025-38303, update your Linux kernel to a version that includes the patch for this vulnerability.
3
What specific component is affected by CVE-2025-38303?
CVE-2025-38303 affects the eir_create_adv_data function within the Bluetooth subsystem of the Linux kernel.
4
What type of vulnerability is CVE-2025-38303?
CVE-2025-38303 is a memory corruption vulnerability that could lead to application crashes.
5
When was CVE-2025-38303 disclosed?
CVE-2025-38303 was disclosed as a part of updates to the Linux kernel addressing multiple vulnerabilities.