#VU119322 Out-of-bounds read in Linux kernel - CVE-2025-40294
Published: December 8, 2025
Vulnerability identifier: #VU119322
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-40294
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the parse_adv_monitor_pattern() function in net/bluetooth/mgmt.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/3a50d59b3781bc3a4e96533612509546a4c309a7
- https://git.kernel.org/stable/c/4b7d4aa5399b5a64caee639275615c63c008540d
- https://git.kernel.org/stable/c/5f7350ff2b179764a4f40ba4161b60b8aaef857b
- https://git.kernel.org/stable/c/8d59fba49362c65332395789fd82771f1028d87e
- https://git.kernel.org/stable/c/96616530f524a0a76248cd44201de0a9e8526190