cbcvebase.
CVE-2025-37792
published 2025-05-01

CVE-2025-37792: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereference The btrtl_initialize() function checks…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereference The btrtl_initialize() function checks that rtl_load_file() either had an error or it loaded a zero length file. However, if it loaded a zero length file then the error code is not set correctly. It results in an error pointer vs NULL bug, followed by a NULL pointer dereference. This was detected by Smatch: drivers/bluetooth/btrtl.c:592 btrtl_initialize() warn: passing zero to 'ERR_PTR'

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < c3e9717276affe59fd8213706db021b493e81e34c3e9717276affe59fd8213706db021b493e81e34
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < 73dc99c0ea94abd22379b2d82cacbc73f3e18ec173dc99c0ea94abd22379b2d82cacbc73f3e18ec1
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < 2d7c60c2a38b4b461fa960ad0995136a6bfe07562d7c60c2a38b4b461fa960ad0995136a6bfe0756
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < d8441818690d795232331bd8358545c5c95b6b72d8441818690d795232331bd8358545c5c95b6b72
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < 3db6605043b50c8bb768547b23e0222f67ceef3e3db6605043b50c8bb768547b23e0222f67ceef3e
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < aaf356f872a60db1e96fb762a62c4607fd22741faaf356f872a60db1e96fb762a62c4607fd22741f
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < 53ceef799dcfc22c734d600811bfc9dd32eaea0a53ceef799dcfc22c734d600811bfc9dd32eaea0a
linuxlinux>= 26503ad25de8c7c93a2037f919c2e49a62cf65f1 < 324dddea321078a6eeb535c2bff5257be74c9799324dddea321078a6eeb535c2bff5257be74c9799
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.19 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.14.46.14.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.