CVE-2025-40282 — Linux vulnerability
49 documents7 sources
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 79.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
Bluetooth 6lowpan.c netdev has header_ops, so it must set link-local
header for RX skb, otherwise things crash, eg. with AF_PACKET SOCK_RAW
Add missing skb_reset_mac_header() for uncompressed ipv6 RX path.
For the compressed one, it is done in lowpan_header_decompress().
Log: (BlueZ 6lowpan-tester Client Recv Raw - Success)
kernel BUG at net/core/skbuff.c:212!
Ca…
Affected Packages7 packages
▶CVEListV5linux/linux18722c247023035b9e2e2a08a887adec2a9a6e49 — ea46a1d217bc82e01cf3d0424e50ebfe251e34bf+8