cbcvebase.
CVE-2025-40294
published 2025-12-08

CVE-2025-40294: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the…

PriorityP421high7.8
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the parse_adv_monitor_pattern() function, the value of the 'length' variable is currently limited to HCI_MAX_EXT_AD_LENGTH(251). The size of the 'value' array in the mgmt_adv_pattern structure is 31. If the value of 'pattern[i].length' is set in the user space and exceeds 31, the 'patterns[i].value' array can be accessed out of bound when copied. Increasing the size of the 'value' array in the 'mgmt_adv_pattern' structure will break the userspace. Considering this, and to avoid OOB access revert the limits for 'offset' and 'length' back to the value of HCI_MAX_AD_LENGTH. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 6.1.83 < 6.1.1596.1.159
linuxlinux>= 99f30e12e588f9982a6eb1916e53510bff25b3b8 < 96616530f524a0a76248cd44201de0a9e852619096616530f524a0a76248cd44201de0a9e8526190
linuxlinux>= db08722fc7d46168fe31d9b8a7b29229dd959f9f < 5f7350ff2b179764a4f40ba4161b60b8aaef857b5f7350ff2b179764a4f40ba4161b60b8aaef857b
linuxlinux>= db08722fc7d46168fe31d9b8a7b29229dd959f9f < 4b7d4aa5399b5a64caee639275615c63c008540d4b7d4aa5399b5a64caee639275615c63c008540d
linuxlinux>= db08722fc7d46168fe31d9b8a7b29229dd959f9f < 3a50d59b3781bc3a4e96533612509546a4c309a73a50d59b3781bc3a4e96533612509546a4c309a7
linuxlinux>= db08722fc7d46168fe31d9b8a7b29229dd959f9f < 8d59fba49362c65332395789fd82771f1028d87e8d59fba49362c65332395789fd82771f1028d87e
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.1.1596.1.159
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.6.0 < 6.12.586.12.58
linuxlinux_kernel>= 6.7.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_redhat7.3MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.