cbcvebase.
CVE-2025-40141
published 2025-11-12

CVE-2025-40141: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free This attempt to fix similar issue to…

PriorityP340high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.29%
21.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free This attempt to fix similar issue to sco_conn_free where if the conn->sk is not set to NULL may lead to UAF on iso_conn_free.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= ccf74f2390d60a2f9a75ef496d2564abb478f46a < eba6d787ec117a5d2c60f9644e0a39c18542b6beeba6d787ec117a5d2c60f9644e0a39c18542b6be
linuxlinux>= ccf74f2390d60a2f9a75ef496d2564abb478f46a < 5319145a07d8bf5b0782b25cb3115825689d42bb5319145a07d8bf5b0782b25cb3115825689d42bb
linuxlinux>= ccf74f2390d60a2f9a75ef496d2564abb478f46a < 80689777919f02328eb873769de4647c9dd3e37180689777919f02328eb873769de4647c9dd3e371
linuxlinux>= ccf74f2390d60a2f9a75ef496d2564abb478f46a < c92ad1a155ccfa38b87bd1d998287e1c0a24248dc92ad1a155ccfa38b87bd1d998287e1c0a24248d
linuxlinux>= ccf74f2390d60a2f9a75ef496d2564abb478f46a < 9950f095d6c875dbe0c9ebfcf972ec88fdf26fc89950f095d6c875dbe0c9ebfcf972ec88fdf26fc8
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.0.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_redhat7.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.