CVE-2025-40141 — Expired Pointer Dereference in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 94.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix possible UAF on iso_conn_free
This attempt to fix similar issue to sco_conn_free where if the
conn->sk is not set to NULL may lead to UAF on iso_conn_free.
Affected Packages6 packages
▶CVEListV5linux/linuxccf74f2390d60a2f9a75ef496d2564abb478f46a — eba6d787ec117a5d2c60f9644e0a39c18542b6be+5