CVE-2025-39982: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
Published Oct 15, 2025
·Updated
Bluetooth: hcievent: Fix UAF in hciaclcreateconnsync
Affected Software
3 affected componentsFixes available
Linux Kernel>=6.16.0-rc7
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.104.2-4
Event History
Oct 15, 2025
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
DescriptionSeverity
Data Sourced
via Red Hat·08:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:15 AM
DescriptionSeverity
Oct 16, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:03 AM
Affected Software
Updated
via Microsoft·01:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-39982?
CVE-2025-39982 is categorized with a moderate severity due to the potential unauthorized access risk in Bluetooth connections.
2
How do I fix CVE-2025-39982?
To resolve CVE-2025-39982, update your Linux Kernel to version 6.16.0-rc8 or later.
3
Which versions of the Linux Kernel are affected by CVE-2025-39982?
CVE-2025-39982 affects Linux Kernel versions from 6.16.0-rc7 and earlier.
4
What does CVE-2025-39982 impact?
CVE-2025-39982 impacts Bluetooth functionality by allowing a use-after-free vulnerability during connection establishment.
5
Is CVE-2025-39982 a critical vulnerability?
Although CVE-2025-39982 poses significant risk, it is not classified as a critical vulnerability, given its moderate severity level.