cbcvebase.
CVE-2025-40213
published 2025-11-24

CVE-2025-40213: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.6th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 302a1f674c00dd5581ab8e493ef44767c5101aab < 1c9aca1787e8395a2c59fef20e914467958969c51c9aca1787e8395a2c59fef20e914467958969c5
linuxlinux>= 302a1f674c00dd5581ab8e493ef44767c5101aab < e8785404de06a69d89dcdd1e9a0b6ea42dc6d327e8785404de06a69d89dcdd1e9a0b6ea42dc6d327
linuxlinux>= 6.16.10 < 6.176.17
linuxlinux>= 6.6.140 < 6.76.7
linuxlinux>= d71b98f253b079cbadc83266383f26fe7e9e103b < 5c19daa93d9af29f1f46251b47e1ea66bcc8d6795c19daa93d9af29f1f46251b47e1ea66bcc8d679
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.17.0 < 6.17.86.17.8
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.