CVE Database
/

CVE-2025-40308

Back to search

CVE-2025-40308

Published: Dec 8, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bcsp: receive data only if registered Currently, bcsp_recv() can be called even when the BCSP protocol has not been registered. This leads to a NULL pointer dereference, as shown in the following stack trace: KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] RIP: 0010:bcsp_recv+0x13d/0x1740 drivers/bluetooth/hci_bcsp.c:590 Call Trace: <TASK> hci_uart_tty_receive+0x194/0x220 drivers/bluetooth/hci_ldisc.c:627 tiocsti+0x23c/0x2c0 drivers/tty/tty_io.c:2290 tty_ioctl+0x626/0xde0 drivers/tty/tty_io.c:2706 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:907 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f To prevent this, ensure that the HCI_UART_REGISTERED flag is set before processing received data. If the protocol is not registered, return -EUNATCH.

VendorProductVersions

Linux

Linux

affected
48effdb7a798232db945503cf3f51e0be8070cea - < 39a7d40314b6288cfa2d13269275e9247a7a055a
affected
45fa7bd82c6178f4fec0ab94891144a043ec5fe8 - < 164586725b47f9d61912e6bf17dbaffeff11710b
affected
d71a57a34ab6bbc95dc461158403c02e8ff3f912 - < b65ca9708bfbf47d8b7bd44b7c574bd16798e9c9
affected
9cf7dccaa7f4c56d2089700e5cb11f85a8d5f6cf - < 8b892dbef3887dbe9afdc7176d1a5fd90e1636aa
affected
806464634e7fc6b523160defeeddb1ade2a72f81 - < 799cd62cbcc3f12ee04b33ef390ff7d41c37d671

+13 more versions

Linux

Linux

affected
6.15
unaffected
0 - < 6.15
unaffected
5.4.302 - <= 5.4.*
unaffected
5.10.247 - <= 5.10.*
unaffected
5.15.197 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now