CVE-2025-40301 — Out-of-bounds Read in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.1%
top 84.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: validate skb length for unknown CC opcode
In hci_cmd_complete_evt(), if the command complete event has an unknown
opcode, we assume the first byte of the remaining skb->data contains the
return status. However, parameter data has previously been pulled in
hci_event_func(), which may leave the skb empty. If so, using skb->data[0]
for the return status uses un-init memory.
The fix is to check skb->len befo…
Affected Packages7 packages
▶CVEListV5linux/linuxafcb3369f46ed5dc883a7b92f2dd1e264d79d388 — fea895de78d3bb2f0c09db9f10b18f8121b15759+5