CVE-2025-38304

MEDIUM EPSS 4.2%
Published Jul 10, 202511mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 10, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIR_SERVICE_DATA.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
4.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.19  –  <6.1.142
linuxlinux_kernel*≥6.2  –  <6.6.94
linuxlinux_kernel*≥6.7  –  <6.12.34
linuxlinux_kernel*≥6.13  –  <6.15.3
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/20a2aa01f5aeb6daad9aeaa7c33dd512c58d81eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/497c9d2d7d3983826bb02c10fb4a5818be6550fb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4bf29910570666e668a60d953f8da78e95bb7fa2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d99cc0f8e6fa0f35570887899f178122a61d44e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/842f7c3154d5b25ca11753c02ee8cf6ee64c0142
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/20a2aa01f5aeb6daad9aeaa7c33dd512c58d81eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/497c9d2d7d3983826bb02c10fb4a5818be6550fb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4bf29910570666e668a60d953f8da78e95bb7fa2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d99cc0f8e6fa0f35570887899f178122a61d44e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/842f7c3154d5b25ca11753c02ee8cf6ee64c0142
    Patch