cbcvebase.
CVE-2025-39861
published 2025-09-19

CVE-2025-39861: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: vhci: Prevent use-after-free by removing debugfs files early Move the creation…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: vhci: Prevent use-after-free by removing debugfs files early Move the creation of debugfs files into a dedicated function, and ensure they are explicitly removed during vhci_release(), before associated data structures are freed. Previously, debugfs files such as "force_suspend", "force_wakeup", and others were created under hdev->debugfs but not removed in vhci_release(). Since vhci_release() frees the backing vhci_data structure, any access to these files after release would result in use-after-free errors. Although hdev->debugfs is later freed in hci_release_dev(), user can access files after vhci_data is freed but before hdev->debugfs is released.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.6-1 (forky)linux 6.16.6-1 (forky)
linuxlinux
linuxlinux>= ab4e4380d4e158486e595013a2635190e07e28ce < bd75eba88e88d7b896b0c737b02a74a12afc235fbd75eba88e88d7b896b0c737b02a74a12afc235f
linuxlinux>= ab4e4380d4e158486e595013a2635190e07e28ce < 1503756fffe76d5aea2371a4b8dee20c3577bcfd1503756fffe76d5aea2371a4b8dee20c3577bcfd
linuxlinux>= ab4e4380d4e158486e595013a2635190e07e28ce < 7cc08f2f127b9a66f46ea918e34353811a7cb3787cc08f2f127b9a66f46ea918e34353811a7cb378
linuxlinux>= ab4e4380d4e158486e595013a2635190e07e28ce < 28010791193a4503f054e8d69a950ef815deb53928010791193a4503f054e8d69a950ef815deb539
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.6-16.16.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13 < 6.16.66.16.6
linuxlinux_kernel>= 6.4 < 6.6.1056.6.105
linuxlinux_kernel>= 6.7 < 6.12.466.12.46
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.