Junglewise Threat Intelligence

CVE-2025-38592: Linux Kernel Bluetooth out-of-bounds read in hci_devcd_dump

CVE-2025-38592 · Severity: high · CVSS 8.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to a system crash. The issue occurs when the system attempts to record diagnostic information (a 'coredump') after a Bluetooth failure; if a previous recording hasn't been processed, the system may incorrectly access memory that has already been freed. This could allow an attacker within Bluetooth range to cause a denial-of-service or potentially gain unauthorized access to system memory.

Technical details

A use-after-free (UAF) vulnerability exists in net/bluetooth/coredump.c within the hci_devcd_dump function. The root cause is a race condition or improper sequencing where dev_coredumpv() may free the hdev->dump.head buffer if a previous coredump has not yet been read by userspace. Subsequent calls to skb_put_data() then attempt to access this freed memory, resulting in a vmalloc-out-of-bounds read. An attacker within Bluetooth range could potentially trigger this condition to cause a kernel panic or leak sensitive information from kernel memory. The fix involves reordering the function calls to ensure diagnostic data is copied to the socket buffer before dev_coredumpv() is invoked.

Affected products

  • Linux Linux Kernel b257e02ecc46 to 7af4d7b53502; 6.15 to 6.15.10; 6.16 to 6.16.1

Timeline

  • 2025-07-17: patched: Initial patch authored
  • 2025-08-19: advisory: CVE published

References

Related threats