CVE-2025-40283: Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
Bluetooth: btusb: reorder cleanup in btusbdisconnect to avoid UAF
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40283?
CVE-2025-40283 has been reported as having a critical severity due to potential use-after-free vulnerabilities in the Bluetooth subsystem of the Linux kernel.
How do I fix CVE-2025-40283?
To fix CVE-2025-40283, update the Linux kernel to the latest stable version that includes the patch for this vulnerability.
What systems are affected by CVE-2025-40283?
CVE-2025-40283 affects all versions of the Linux kernel with Bluetooth functionality that use the btusb driver.
What are the risks of CVE-2025-40283?
The risks of CVE-2025-40283 include potential exploitation leading to remote code execution or system crashes affecting the stability of the affected systems.
Is CVE-2025-40283 being actively exploited?
As of the latest information, there is no public indication that CVE-2025-40283 is being actively exploited in the wild, but it is advisable to apply patches promptly.