PT-2025-14350 · Linux+9 · Linux Kernel+9

Published

2025-01-16

·

Updated

2026-05-26

·

CVE-2025-21969

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc5
Description A slab-use-after-free read vulnerability has been identified in the Linux kernel's Bluetooth L2CAP implementation. The issue occurs when the hci sync command releases l2cap conn, and the hci receive data work queue references the released l2cap conn when sending to the upper layer. This can be resolved by adding an hci dev lock to the hci receive data work queue to synchronize the two. The vulnerability can cause a read of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the slab-use-after-free read vulnerability in the Bluetooth L2CAP implementation. As a temporary workaround, consider disabling the Bluetooth L2CAP functionality until a patch is available. Restrict access to the vulnerable l2cap send cmd function to minimize the risk of exploitation. Avoid using the l2cap conn variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:9080
ALT-PU-2025-12647
ALT-PU-2025-5786
AZL-60251
AZL-60270
BDU:2025-10246
CVE-2025-21969
ECHO-6BF4-CE35-C2F3
INFSA-2025_9080
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-2077
OESA-2025-2078
OESA-2025-2079
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:9079
RHSA-2025:9080
RHSA-2025_9080
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:03613-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:1293-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_1293-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu