CVE-2025-38303
HIGH severity · CVSS 7.8
7.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/2af40d795d3fb0ee5c074b7ac56ab22402aa6e4fPatch
- https://git.kernel.org/stable/c/47c03902269aff377f959dc3fd94a9733aa31d6ePatch
- https://git.kernel.org/stable/c/b9db0c27e73b7c8a19384a44af527edfda74ff3dPatch
- https://git.kernel.org/stable/c/2d4588f55cc10fc228f3b46469dbfb3f0a8b13c8