Executive brief
A vulnerability was identified in the Linux kernel's Bluetooth subsystem that could lead to a system crash. The issue occurs when the system attempts to record diagnostic information (a 'coredump') after a Bluetooth failure; if a previous recording hasn't been processed, the system may incorrectly access memory that has already been freed. This could allow an attacker within Bluetooth range to cause a denial-of-service or potentially gain unauthorized access to system memory.
Technical details
A use-after-free (UAF) vulnerability exists in net/bluetooth/coredump.c within the hci_devcd_dump function. The root cause is a race condition or improper sequencing where dev_coredumpv() may free the hdev->dump.head buffer if a previous coredump has not yet been read by userspace. Subsequent calls to skb_put_data() then attempt to access this freed memory, resulting in a vmalloc-out-of-bounds read. An attacker within Bluetooth range could potentially trigger this condition to cause a kernel panic or leak sensitive information from kernel memory. The fix involves reordering the function calls to ensure diagnostic data is copied to the socket buffer before dev_coredumpv() is invoked.
Affected products
- Linux Linux Kernel b257e02ecc46 to 7af4d7b53502; 6.15 to 6.15.10; 6.16 to 6.16.1
Timeline
- 2025-07-17: patched: Initial patch authored
- 2025-08-19: advisory: CVE published