CVE-2025-40284 — Signal Handler Race Condition in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.1%
top 84.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: cancel mesh send timer when hdev removed
mesh_send_done timer is not canceled when hdev is removed, which causes
crash if the timer triggers after hdev is gone.
Cancel the timer when MGMT removes the hdev, like other MGMT timers.
Should fix the BUG: sporadically seen by BlueZ test bot
(in "Mesh - Send cancel - 1" test).
Log:
BUG: KASAN: slab-use-after-free in run_timer_softirq+0x76b/0x7d0
...
Freed by task …
Affected Packages7 packages
▶CVEListV5linux/linuxb338d91703fae6f6afd67f3f75caa3b8f36ddef3 — 990e6143b0ca0c66f099d67d00c112bf59b30d76+5