CVE-2025-68304: Bluetooth: hci_core: lookup hci_conn on RX path on protocol side
Published Dec 16, 2025
·Updated
Bluetooth: hcicore: lookup hciconn on RX path on protocol side
Affected Software
2 affected components
Linux
Microsoft azl3 kernel 6.6.117.1-1
Event History
Dec 16, 2025
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverity
Data Sourced
via NVD·04:16 PM
DescriptionSeverity
Dec 18, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-68304?
CVE-2025-68304 has been classified with a medium severity level due to potential information disclosure risks.
2
How do I fix CVE-2025-68304?
To fix CVE-2025-68304, update your Linux kernel to the latest patched version provided by your distribution.
3
What systems are affected by CVE-2025-68304?
CVE-2025-68304 affects Linux systems that utilize the Bluetooth stack, particularly those with active Bluetooth connections.
4
What are the potential impacts of CVE-2025-68304?
The potential impacts of CVE-2025-68304 include the risk of denial of service or unexpected behavior in Bluetooth operations.
5
How can I verify if my system is vulnerable to CVE-2025-68304?
You can verify if your system is vulnerable to CVE-2025-68304 by checking for the presence of the affected kernel version and reviewing the patch notes from your Linux distribution.