CVE-2025-38315

MEDIUM EPSS 3.3%
Published Jul 10, 202511mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 10, 2025 11mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct btintel_dsbr is already known, we can just start there instead of querying the EFI variable size. If the final result doesn't match what we expect also fail. This fixes a stack buffer overflow when the EFI variable is larger than struct btintel_dsbr.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
3.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-674

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel*≥6.11.1  –  <6.12.34
linuxlinux_kernel*≥6.13  –  <6.15.3
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any

References 3

  • git.kernel.org https://git.kernel.org/stable/c/3aa1dc3c9060e335e82e9c182bf3d1db29220b1b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b8526bb489780ccc0caffc446ecabec83cfe568
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9427f6081f37c795a8bd29d0ee72a4da3bd64af8
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3aa1dc3c9060e335e82e9c182bf3d1db29220b1b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b8526bb489780ccc0caffc446ecabec83cfe568
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9427f6081f37c795a8bd29d0ee72a4da3bd64af8
    Patch