Bluetooth Vulnerability in Linux Kernel Affects Multiple Devices
CVE-2025-21969

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
1 April 2025

What is CVE-2025-21969?

A vulnerability has been identified in the Linux kernel's Bluetooth subsystem, specifically within the L2CAP layer. This issue occurs due to a slab-use-after-free scenario in the l2cap_send_cmd function. When the HCI sync command releases the l2cap_conn, the associated work queue for receiving HCI data refers to a deallocated l2cap_conn, leading to potential memory access violations. To address this, a locking mechanism has been introduced to ensure proper synchronization between the connection release and data processing. This fix is crucial for safeguarding Bluetooth communications in various devices utilizing the affected kernel version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 9b3628d79b46f06157affc56fdb218fdd4988321

Linux 9b3628d79b46f06157affc56fdb218fdd4988321

Linux 9b3628d79b46f06157affc56fdb218fdd4988321 < 7790a79c6fce8d5d552bc64f5c82819f719e4f28

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.