In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Disable SCO support if READVOICESETTING is unsupported/broken
A SCO connection without the proper voice_setting can cause the controller to lock up.
[
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "33600605404974934639766620267511136824",
"length": 840.0
},
"id": "CVE-2025-38099-0003b2d2",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ec1f015ec0c6fd250a6564e8452f7bb3160b9cb1",
"target": {
"function": "hci_cc_read_buffer_size",
"file": "net/bluetooth/hci_event.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"287564312158077670275969380029772800524",
"154997033792159671248663236623436848141",
"19181235516504674753441461130342854461"
]
},
"id": "CVE-2025-38099-22689128",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@14d17c78a4b1660c443bae9d38c814edea506f62",
"target": {
"file": "net/bluetooth/hci_event.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "33600605404974934639766620267511136824",
"length": 840.0
},
"id": "CVE-2025-38099-845e9e93",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f48ee562c095e552a30b8d9cc0566a267b410f8a",
"target": {
"function": "hci_cc_read_buffer_size",
"file": "net/bluetooth/hci_event.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "33600605404974934639766620267511136824",
"length": 840.0
},
"id": "CVE-2025-38099-8574934f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@14d17c78a4b1660c443bae9d38c814edea506f62",
"target": {
"function": "hci_cc_read_buffer_size",
"file": "net/bluetooth/hci_event.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"287564312158077670275969380029772800524",
"154997033792159671248663236623436848141",
"19181235516504674753441461130342854461"
]
},
"id": "CVE-2025-38099-886c5628",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f48ee562c095e552a30b8d9cc0566a267b410f8a",
"target": {
"file": "net/bluetooth/hci_event.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"287564312158077670275969380029772800524",
"154997033792159671248663236623436848141",
"19181235516504674753441461130342854461"
]
},
"id": "CVE-2025-38099-bb31ed51",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ec1f015ec0c6fd250a6564e8452f7bb3160b9cb1",
"target": {
"file": "net/bluetooth/hci_event.c"
}
}
]