PT-2025-42258 · Linux+1 · Linux Kernel+1

Published

2025-09-20

·

Updated

2025-12-08

·

CVE-2025-39983

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.16-rc7
Description The Linux kernel contains a use-after-free flaw within the Bluetooth stack, specifically in the hci conn tx dequeue function. This issue arises from improper locking of the hdev structure when processing HCI EV NUM COMP PKTS events, leading to a potential use-after-free condition. The vulnerability was identified through KASAN (Kernel Address Sanitizer) testing and is triggered during the handling of Bluetooth events.
Recommendations Update to a version newer than 6.16-rc7.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:22854
BDU:2026-03910
CVE-2025-39983
INFSA-2025_21469
RHSA-2025_21469
RHSA-2026:0271
RHSA-2026:0457

Affected Products

Linux Kernel
Red Hat