cbcvebase.
CVE-2025-40308
published 2025-12-08

CVE-2025-40308: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bcsp: receive data only if registered Currently, bcsp_recv() can be called even…

PriorityP419high7.8
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bcsp: receive data only if registered Currently, bcsp_recv() can be called even when the BCSP protocol has not been registered. This leads to a NULL pointer dereference, as shown in the following stack trace: KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] RIP: 0010:bcsp_recv+0x13d/0x1740 drivers/bluetooth/hci_bcsp.c:590 Call Trace: hci_uart_tty_receive+0x194/0x220 drivers/bluetooth/hci_ldisc.c:627 tiocsti+0x23c/0x2c0 drivers/tty/tty_io.c:2290 tty_ioctl+0x626/0xde0 drivers/tty/tty_io.c:2706 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:907 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f To prevent this, ensure that the HCI_UART_REGISTERED flag is set before processing received data. If the protocol is not registered, return -EUNATCH.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 366ceff495f902182d42b6f41525c2474caf3f9a < 55c1519fca830f59a10bbf9aa8209c87b06cf7bc55c1519fca830f59a10bbf9aa8209c87b06cf7bc
linuxlinux>= 366ceff495f902182d42b6f41525c2474caf3f9a < ca94b2b036c22556c3a66f1b80f490882deef7a6ca94b2b036c22556c3a66f1b80f490882deef7a6
linuxlinux>= 45fa7bd82c6178f4fec0ab94891144a043ec5fe8 < 164586725b47f9d61912e6bf17dbaffeff11710b164586725b47f9d61912e6bf17dbaffeff11710b
linuxlinux>= 48effdb7a798232db945503cf3f51e0be8070cea < 39a7d40314b6288cfa2d13269275e9247a7a055a39a7d40314b6288cfa2d13269275e9247a7a055a
linuxlinux>= 5.10.237 < 5.10.2475.10.247
linuxlinux>= 5.15.181 < 5.15.1975.15.197
linuxlinux>= 5.4.293 < 5.4.3025.4.302
linuxlinux>= 6.1.135 < 6.1.1596.1.159
linuxlinux>= 6.12.24 < 6.12.586.12.58
linuxlinux>= 6.13.12 < 6.146.14
linuxlinux>= 6.14.3 < 6.156.15
linuxlinux>= 6.6.88 < 6.6.1176.6.117
linuxlinux>= 6b7a32fa9bacdebd98c18b2a56994116995ee643 < b420a4c7f915fc1c94ad1f6ca740acc046d94334b420a4c7f915fc1c94ad1f6ca740acc046d94334
linuxlinux>= 806464634e7fc6b523160defeeddb1ade2a72f81 < 799cd62cbcc3f12ee04b33ef390ff7d41c37d671799cd62cbcc3f12ee04b33ef390ff7d41c37d671
linuxlinux>= 9cf7dccaa7f4c56d2089700e5cb11f85a8d5f6cf < 8b892dbef3887dbe9afdc7176d1a5fd90e1636aa8b892dbef3887dbe9afdc7176d1a5fd90e1636aa
linuxlinux>= d71a57a34ab6bbc95dc461158403c02e8ff3f912 < b65ca9708bfbf47d8b7bd44b7c574bd16798e9c9b65ca9708bfbf47d8b7bd44b7c574bd16798e9c9
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat4.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.