cbcvebase.
CVE-2025-38304
published 2025-07-10

CVE-2025-38304: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIR_SERVICE_DATA.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 497c9d2d7d3983826bb02c10fb4a5818be6550fb497c9d2d7d3983826bb02c10fb4a5818be6550fb
linuxlinux>= 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 4bf29910570666e668a60d953f8da78e95bb7fa24bf29910570666e668a60d953f8da78e95bb7fa2
linuxlinux>= 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 842f7c3154d5b25ca11753c02ee8cf6ee64c0142842f7c3154d5b25ca11753c02ee8cf6ee64c0142
linuxlinux>= 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 7d99cc0f8e6fa0f35570887899f178122a61d44e7d99cc0f8e6fa0f35570887899f178122a61d44e
linuxlinux>= 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 20a2aa01f5aeb6daad9aeaa7c33dd512c58d81eb20a2aa01f5aeb6daad9aeaa7c33dd512c58d81eb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.19 < 6.1.1426.1.142
linuxlinux_kernel>= 6.13 < 6.15.36.15.3
linuxlinux_kernel>= 6.2 < 6.6.946.6.94
linuxlinux_kernel>= 6.7 < 6.12.346.12.34
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM