CVE-2025-40308 — NULL Pointer Dereference in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 78.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bcsp: receive data only if registered
Currently, bcsp_recv() can be called even when the BCSP protocol has not
been registered. This leads to a NULL pointer dereference, as shown in
the following stack trace:
KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f]
RIP: 0010:bcsp_recv+0x13d/0x1740 drivers/bluetooth/hci_bcsp.c:590
Call Trace:
hci_uart_tty_receive+0x194/0x220 drivers/bluetooth/hci_ldis…
Affected Packages7 packages
▶CVEListV5linux/linux48effdb7a798232db945503cf3f51e0be8070cea — 39a7d40314b6288cfa2d13269275e9247a7a055a+10