CVE-2025-38250

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38250
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38250.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38250
Downstream
Related
Published
2025-07-09T10:42:30Z
Modified
2025-10-18T03:36:50.181174Z
Summary
Bluetooth: hci_core: Fix use-after-free in vhci_flush()
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hcicore: Fix use-after-free in vhciflush()

syzbot reported use-after-free in vhci_flush() without repro. [0]

From the splat, a thread close()d a vhci file descriptor while its device was being used by iotcl() on another thread.

Once the last fd refcnt is released, vhcirelease() calls hciunregisterdev(), hcifreedev(), and kfree() for struct vhcidata, which is set to hcidev->dev->driverdata.

The problem is that there is no synchronisation after unlinking hdev from hcidevlist in hciunregisterdev(). There might be another thread still accessing the hdev which was fetched before the unlink operation.

We can use SRCU for such synchronisation.

Let's run hcidevreset() under SRCU and wait for its completion in hciunregisterdev().

Another option would be to restore hcidev->destruct(), which was removed in commit 587ae086f6e4 ("Bluetooth: Remove unused hci-destruct cb"). However, this would not be a good solution, as we should not run hciunregister_dev() while there are in-flight ioctl() requests, which could lead to another data-race KCSAN splat.

Note that other drivers seem to have the same problem, for exmaple, virtbt_remove().

BUG: KASAN: slab-use-after-free in skbqueuepurge_reason+0x99/0x360 net/core/skbuff.c:3937 Read of size 8 at addr ffff88807cb8d858 by task syz.1.219/6718

CPU: 1 UID: 0 PID: 6718 Comm: syz.1.219 Not tainted 6.16.0-rc1-syzkaller-00196-g08207f42d3ff #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 Call Trace: <TASK> dumpstacklvl+0x189/0x250 lib/dumpstack.c:120 printaddressdescription mm/kasan/report.c:408 [inline] printreport+0xd2/0x2b0 mm/kasan/report.c:521 kasanreport+0x118/0x150 mm/kasan/report.c:634 skbqueueemptylockless include/linux/skbuff.h:1891 [inline] skbqueuepurgereason+0x99/0x360 net/core/skbuff.c:3937 skbqueuepurge include/linux/skbuff.h:3368 [inline] vhciflush+0x44/0x50 drivers/bluetooth/hcivhci.c:69 hcidevdoreset net/bluetooth/hcicore.c:552 [inline] hcidevreset+0x420/0x5c0 net/bluetooth/hcicore.c:592 sockdoioctl+0xd9/0x300 net/socket.c:1190 sockioctl+0x576/0x790 net/socket.c:1311 vfsioctl fs/ioctl.c:51 [inline] _dosysioctl fs/ioctl.c:907 [inline] _sesysioctl+0xf9/0x170 fs/ioctl.c:893 dosyscallx64 arch/x86/entry/syscall64.c:63 [inline] dosyscall64+0xfa/0x3b0 arch/x86/entry/syscall64.c:94 entrySYSCALL64afterhwframe+0x77/0x7f RIP: 0033:0x7fcf5b98e929 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fcf5c7b9038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fcf5bbb6160 RCX: 00007fcf5b98e929 RDX: 0000000000000000 RSI: 00000000400448cb RDI: 0000000000000009 RBP: 00007fcf5ba10b39 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 00007fcf5bbb6160 R15: 00007ffd6353d528 </TASK>

Allocated by task 6535: kasansavestack mm/kasan/common.c:47 [inline] kasansavetrack+0x3e/0x80 mm/kasan/common.c:68 poisonkmallocredzone mm/kasan/common.c:377 [inline] _kasankmalloc+0x93/0xb0 mm/kasan/common.c:394 kasankmalloc include/linux/kasan.h:260 [inline] _kmalloccachenoprof+0x230/0x3d0 mm/slub.c:4359 kmallocnoprof include/linux/slab.h:905 [inline] kzallocnoprof include/linux/slab.h:1039 [inline] vhciopen+0x57/0x360 drivers/bluetooth/hcivhci.c:635 miscopen+0x2bc/0x330 drivers/char/misc.c:161 chrdevopen+0x4c9/0x5e0 fs/chardev.c:414 dodentryopen+0xdf0/0x1970 fs/open.c:964 vfsopen+0x3b/0x340 fs/open.c:1094 doopen fs/namei.c:3887 [inline] pathopenat+0x2ee5/0x3830 fs/name ---truncated---

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf18c7118cf83ad4b9aa476354b4a06bcb9d0c4f
Fixed
bc0819a25e04cd68ef3568cfa51b63118fea39a7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf18c7118cf83ad4b9aa476354b4a06bcb9d0c4f
Fixed
ce23b73f0f27e2dbeb81734a79db710f05aa33c6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf18c7118cf83ad4b9aa476354b4a06bcb9d0c4f
Fixed
0e5c144c557df910ab64d9c25d06399a9a735e65
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf18c7118cf83ad4b9aa476354b4a06bcb9d0c4f
Fixed
1d6123102e9fbedc8d25bf4731da6d513173e49e

Affected versions

v3.*

v3.10
v3.10-rc1
v3.10-rc2
v3.10-rc3
v3.10-rc4
v3.10-rc5
v3.10-rc6
v3.10-rc7
v3.11
v3.11-rc1
v3.11-rc2
v3.11-rc3
v3.11-rc4
v3.11-rc5
v3.11-rc6
v3.11-rc7
v3.12
v3.12-rc1
v3.12-rc2
v3.12-rc3
v3.12-rc4
v3.12-rc5
v3.12-rc6
v3.12-rc7
v3.13
v3.13-rc1
v3.13-rc2
v3.13-rc3
v3.13-rc4
v3.13-rc5
v3.13-rc6
v3.13-rc7
v3.13-rc8
v3.14
v3.14-rc1
v3.14-rc2
v3.14-rc3
v3.14-rc4
v3.14-rc5
v3.14-rc6
v3.14-rc7
v3.14-rc8
v3.15
v3.15-rc1
v3.15-rc2
v3.15-rc3
v3.15-rc4
v3.15-rc5
v3.15-rc6
v3.15-rc7
v3.15-rc8
v3.16
v3.16-rc1
v3.16-rc2
v3.16-rc3
v3.16-rc4
v3.16-rc5
v3.16-rc6
v3.16-rc7
v3.17
v3.17-rc1
v3.17-rc2
v3.17-rc3
v3.17-rc4
v3.17-rc5
v3.17-rc6
v3.17-rc7
v3.18
v3.18-rc1
v3.18-rc2
v3.18-rc3
v3.18-rc4
v3.18-rc5
v3.18-rc6
v3.18-rc7
v3.19
v3.19-rc1
v3.19-rc2
v3.19-rc3
v3.19-rc4
v3.19-rc5
v3.19-rc6
v3.19-rc7
v3.3
v3.3-rc1
v3.3-rc2
v3.3-rc3
v3.3-rc4
v3.3-rc5
v3.3-rc6
v3.3-rc7
v3.4
v3.4-rc1
v3.4-rc2
v3.4-rc3
v3.4-rc4
v3.4-rc5
v3.4-rc6
v3.4-rc7
v3.5
v3.5-rc1
v3.5-rc2
v3.5-rc3
v3.5-rc4
v3.5-rc5
v3.5-rc6
v3.5-rc7
v3.6
v3.6-rc1
v3.6-rc2
v3.6-rc3
v3.6-rc4
v3.6-rc5
v3.6-rc6
v3.6-rc7
v3.7
v3.7-rc1
v3.7-rc2
v3.7-rc3
v3.7-rc4
v3.7-rc5
v3.7-rc6
v3.7-rc7
v3.7-rc8
v3.8
v3.8-rc1
v3.8-rc2
v3.8-rc3
v3.8-rc4
v3.8-rc5
v3.8-rc6
v3.8-rc7
v3.9
v3.9-rc1
v3.9-rc2
v3.9-rc3
v3.9-rc4
v3.9-rc5
v3.9-rc6
v3.9-rc7
v3.9-rc8

v4.*

v4.0
v4.0-rc1
v4.0-rc2
v4.0-rc3
v4.0-rc4
v4.0-rc5
v4.0-rc6
v4.0-rc7
v4.1
v4.1-rc1
v4.1-rc2
v4.1-rc3
v4.1-rc4
v4.1-rc5
v4.1-rc6
v4.1-rc7
v4.1-rc8
v4.10
v4.10-rc1
v4.10-rc2
v4.10-rc3
v4.10-rc4
v4.10-rc5
v4.10-rc6
v4.10-rc7
v4.10-rc8
v4.11
v4.11-rc1
v4.11-rc2
v4.11-rc3
v4.11-rc4
v4.11-rc5
v4.11-rc6
v4.11-rc7
v4.11-rc8
v4.12
v4.12-rc1
v4.12-rc2
v4.12-rc3
v4.12-rc4
v4.12-rc5
v4.12-rc6
v4.12-rc7
v4.13
v4.13-rc1
v4.13-rc2
v4.13-rc3
v4.13-rc4
v4.13-rc5
v4.13-rc6
v4.13-rc7
v4.14
v4.14-rc1
v4.14-rc2
v4.14-rc3
v4.14-rc4
v4.14-rc5
v4.14-rc6
v4.14-rc7
v4.14-rc8
v4.15
v4.15-rc1
v4.15-rc2
v4.15-rc3
v4.15-rc4
v4.15-rc5
v4.15-rc6
v4.15-rc7
v4.15-rc8
v4.15-rc9
v4.16
v4.16-rc1
v4.16-rc2
v4.16-rc3
v4.16-rc4
v4.16-rc5
v4.16-rc6
v4.16-rc7
v4.17
v4.17-rc1
v4.17-rc2
v4.17-rc3
v4.17-rc4
v4.17-rc5
v4.17-rc6
v4.17-rc7
v4.18
v4.18-rc1
v4.18-rc2
v4.18-rc3
v4.18-rc4
v4.18-rc5
v4.18-rc6
v4.18-rc7
v4.18-rc8
v4.19
v4.19-rc1
v4.19-rc2
v4.19-rc3
v4.19-rc4
v4.19-rc5
v4.19-rc6
v4.19-rc7
v4.19-rc8
v4.2
v4.2-rc1
v4.2-rc2
v4.2-rc3
v4.2-rc4
v4.2-rc5
v4.2-rc6
v4.2-rc7
v4.2-rc8
v4.20
v4.20-rc1
v4.20-rc2
v4.20-rc3
v4.20-rc4
v4.20-rc5
v4.20-rc6
v4.20-rc7
v4.3
v4.3-rc1
v4.3-rc2
v4.3-rc3
v4.3-rc4
v4.3-rc5
v4.3-rc6
v4.3-rc7
v4.4
v4.4-rc1
v4.4-rc2
v4.4-rc3
v4.4-rc4
v4.4-rc5
v4.4-rc6
v4.4-rc7
v4.4-rc8
v4.5
v4.5-rc1
v4.5-rc2
v4.5-rc3
v4.5-rc4
v4.5-rc5
v4.5-rc6
v4.5-rc7
v4.6
v4.6-rc1
v4.6-rc2
v4.6-rc3
v4.6-rc4
v4.6-rc5
v4.6-rc6
v4.6-rc7
v4.7
v4.7-rc1
v4.7-rc2
v4.7-rc3
v4.7-rc4
v4.7-rc5
v4.7-rc6
v4.7-rc7
v4.8
v4.8-rc1
v4.8-rc2
v4.8-rc3
v4.8-rc4
v4.8-rc5
v4.8-rc6
v4.8-rc7
v4.8-rc8
v4.9
v4.9-rc1
v4.9-rc2
v4.9-rc3
v4.9-rc4
v4.9-rc5
v4.9-rc6
v4.9-rc7
v4.9-rc8

v5.*

v5.0
v5.0-rc1
v5.0-rc2
v5.0-rc3
v5.0-rc4
v5.0-rc5
v5.0-rc6
v5.0-rc7
v5.0-rc8
v5.1
v5.1-rc1
v5.1-rc2
v5.1-rc3
v5.1-rc4
v5.1-rc5
v5.1-rc6
v5.1-rc7
v5.10
v5.10-rc1
v5.10-rc2
v5.10-rc3
v5.10-rc4
v5.10-rc5
v5.10-rc6
v5.10-rc7
v5.11
v5.11-rc1
v5.11-rc2
v5.11-rc3
v5.11-rc4
v5.11-rc5
v5.11-rc6
v5.11-rc7
v5.12
v5.12-rc1
v5.12-rc1-dontuse
v5.12-rc2
v5.12-rc3
v5.12-rc4
v5.12-rc5
v5.12-rc6
v5.12-rc7
v5.12-rc8
v5.13
v5.13-rc1
v5.13-rc2
v5.13-rc3
v5.13-rc4
v5.13-rc5
v5.13-rc6
v5.13-rc7
v5.14
v5.14-rc1
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.19
v5.19-rc1
v5.19-rc2
v5.19-rc3
v5.19-rc4
v5.19-rc5
v5.19-rc6
v5.19-rc7
v5.19-rc8
v5.2
v5.2-rc1
v5.2-rc2
v5.2-rc3
v5.2-rc4
v5.2-rc5
v5.2-rc6
v5.2-rc7
v5.3
v5.3-rc1
v5.3-rc2
v5.3-rc3
v5.3-rc4
v5.3-rc5
v5.3-rc6
v5.3-rc7
v5.3-rc8
v5.4
v5.4-rc1
v5.4-rc2
v5.4-rc3
v5.4-rc4
v5.4-rc5
v5.4-rc6
v5.4-rc7
v5.4-rc8
v5.5
v5.5-rc1
v5.5-rc2
v5.5-rc3
v5.5-rc4
v5.5-rc5
v5.5-rc6
v5.5-rc7
v5.6
v5.6-rc1
v5.6-rc2
v5.6-rc3
v5.6-rc4
v5.6-rc5
v5.6-rc6
v5.6-rc7
v5.7
v5.7-rc1
v5.7-rc2
v5.7-rc3
v5.7-rc4
v5.7-rc5
v5.7-rc6
v5.7-rc7
v5.8
v5.8-rc1
v5.8-rc2
v5.8-rc3
v5.8-rc4
v5.8-rc5
v5.8-rc6
v5.8-rc7
v5.9
v5.9-rc1
v5.9-rc2
v5.9-rc3
v5.9-rc4
v5.9-rc5
v5.9-rc6
v5.9-rc7
v5.9-rc8

v6.*

v6.0
v6.0-rc1
v6.0-rc2
v6.0-rc3
v6.0-rc4
v6.0-rc5
v6.0-rc6
v6.0-rc7
v6.1
v6.1-rc1
v6.1-rc2
v6.1-rc3
v6.1-rc4
v6.1-rc5
v6.1-rc6
v6.1-rc7
v6.1-rc8
v6.10
v6.10-rc1
v6.10-rc2
v6.10-rc3
v6.10-rc4
v6.10-rc5
v6.10-rc6
v6.10-rc7
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1
v6.12.10
v6.12.11
v6.12.12
v6.12.13
v6.12.14
v6.12.15
v6.12.16
v6.12.17
v6.12.18
v6.12.19
v6.12.2
v6.12.20
v6.12.21
v6.12.22
v6.12.23
v6.12.24
v6.12.25
v6.12.26
v6.12.27
v6.12.28
v6.12.29
v6.12.3
v6.12.30
v6.12.31
v6.12.32
v6.12.33
v6.12.34
v6.12.35
v6.12.4
v6.12.5
v6.12.6
v6.12.7
v6.12.8
v6.12.9
v6.13
v6.13-rc1
v6.13-rc2
v6.13-rc3
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.13-rc7
v6.14
v6.14-rc1
v6.14-rc2
v6.14-rc3
v6.14-rc4
v6.14-rc5
v6.14-rc6
v6.14-rc7
v6.15
v6.15-rc1
v6.15-rc2
v6.15-rc3
v6.15-rc4
v6.15-rc5
v6.15-rc6
v6.15-rc7
v6.15.1
v6.15.2
v6.15.3
v6.15.4
v6.16-rc1
v6.16-rc2
v6.2
v6.2-rc1
v6.2-rc2
v6.2-rc3
v6.2-rc4
v6.2-rc5
v6.2-rc6
v6.2-rc7
v6.2-rc8
v6.3
v6.3-rc1
v6.3-rc2
v6.3-rc3
v6.3-rc4
v6.3-rc5
v6.3-rc6
v6.3-rc7
v6.4
v6.4-rc1
v6.4-rc2
v6.4-rc3
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.6.1
v6.6.10
v6.6.11
v6.6.12
v6.6.13
v6.6.14
v6.6.15
v6.6.16
v6.6.17
v6.6.18
v6.6.19
v6.6.2
v6.6.20
v6.6.21
v6.6.22
v6.6.23
v6.6.24
v6.6.25
v6.6.26
v6.6.27
v6.6.28
v6.6.29
v6.6.3
v6.6.30
v6.6.31
v6.6.32
v6.6.33
v6.6.34
v6.6.35
v6.6.36
v6.6.37
v6.6.38
v6.6.39
v6.6.4
v6.6.40
v6.6.41
v6.6.42
v6.6.43
v6.6.44
v6.6.45
v6.6.46
v6.6.47
v6.6.48
v6.6.49
v6.6.5
v6.6.50
v6.6.51
v6.6.52
v6.6.53
v6.6.54
v6.6.55
v6.6.56
v6.6.57
v6.6.58
v6.6.59
v6.6.6
v6.6.60
v6.6.61
v6.6.62
v6.6.63
v6.6.64
v6.6.65
v6.6.66
v6.6.67
v6.6.68
v6.6.69
v6.6.7
v6.6.70
v6.6.71
v6.6.72
v6.6.73
v6.6.74
v6.6.75
v6.6.76
v6.6.77
v6.6.78
v6.6.79
v6.6.8
v6.6.80
v6.6.81
v6.6.82
v6.6.83
v6.6.84
v6.6.85
v6.6.86
v6.6.87
v6.6.88
v6.6.89
v6.6.9
v6.6.90
v6.6.91
v6.6.92
v6.6.93
v6.6.94
v6.6.95
v6.6.96
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.9
v6.9-rc1
v6.9-rc2
v6.9-rc3
v6.9-rc4
v6.9-rc5
v6.9-rc6
v6.9-rc7

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-02db3e3e",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_reset",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "278928399992180678510816322500386894448",
            "length": 418.0
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-04170fc3",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "include/net/bluetooth/hci_core.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "106196184799633052284294279222813282009",
                "275056385033110411830936956058217273675",
                "259942651842730034887740296301704717149",
                "259662397359439776566559537067476372769",
                "59520468866835026619420159718565430065",
                "132066140372301669209636425670959248026",
                "70600800260332437768414148103471773342",
                "280740854900640219400918661551144112872"
            ]
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-0e16a331",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "80129253253061740067487708030095149486",
                "263399525196561385669232865061010247743",
                "331625945996439791403563373854863959262",
                "20083222743231906119217925802603213539",
                "319814484023847758208038088701389051304",
                "28774360149078570907428716678912736699",
                "316044724746173805471656069261766804838",
                "175984556566257590969819529720512806523",
                "181789517818256255783256910958794831418",
                "307538052428778242930682639395128684887",
                "220579718742990962498494136710049928108",
                "264990308291589138267027048244707339358",
                "292874667613018504835064712093903147810",
                "225998145572502031619934384776436925536",
                "90376410453211397509737514594637555940",
                "115809259333594453341921524337513220715",
                "90874657339490187821222965573850928396",
                "171039570356542300112428946160698160122",
                "191008653304398227820054449043798755510",
                "188276804667093766077218408479248089281",
                "178032849155355310892978702827690467034",
                "17066088356490712992059728026855063179",
                "85311724638334798139320755343995160881",
                "272914272454073212942862824222930754499",
                "212399008438049892395570948588703519196",
                "132453222626100081109911874558041729535"
            ]
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-26dde9b7",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_get",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "294367607555203296491395321404569894747",
            "length": 326.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-31e63595",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_alloc_dev_priv",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "119359151509322460895433990163054008786",
            "length": 4197.0
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-329250f1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "include/net/bluetooth/hci_core.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "106196184799633052284294279222813282009",
                "275056385033110411830936956058217273675",
                "162666568369510704533150240307404457361",
                "268267584656672530515453214697017029397",
                "59520468866835026619420159718565430065",
                "132066140372301669209636425670959248026",
                "70600800260332437768414148103471773342",
                "280740854900640219400918661551144112872"
            ]
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-39f9d4c2",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_get",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "294367607555203296491395321404569894747",
            "length": 326.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-41e7d0fa",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_unregister_dev",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "38777979769709700142436650796305740622",
            "length": 993.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-51122bfd",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_unregister_dev",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "38777979769709700142436650796305740622",
            "length": 993.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-5845ffd6",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_alloc_dev_priv",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "119359151509322460895433990163054008786",
            "length": 4197.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-5e230325",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_reset",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "278928399992180678510816322500386894448",
            "length": 418.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-607f654e",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_alloc_dev_priv",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "106419855196726375210871239406991118917",
            "length": 4082.0
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-796bb912",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "80129253253061740067487708030095149486",
                "263399525196561385669232865061010247743",
                "331625945996439791403563373854863959262",
                "20083222743231906119217925802603213539",
                "319814484023847758208038088701389051304",
                "28774360149078570907428716678912736699",
                "316044724746173805471656069261766804838",
                "175984556566257590969819529720512806523",
                "181789517818256255783256910958794831418",
                "307538052428778242930682639395128684887",
                "220579718742990962498494136710049928108",
                "264990308291589138267027048244707339358",
                "292874667613018504835064712093903147810",
                "225998145572502031619934384776436925536",
                "90376410453211397509737514594637555940",
                "115809259333594453341921524337513220715",
                "90874657339490187821222965573850928396",
                "171039570356542300112428946160698160122",
                "191008653304398227820054449043798755510",
                "188276804667093766077218408479248089281",
                "178032849155355310892978702827690467034",
                "17066088356490712992059728026855063179",
                "85311724638334798139320755343995160881",
                "220388800022935526975857345201906671659",
                "65227625801266657636005257804726981618",
                "205594349721985759561621612482184923428"
            ]
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-87d99601",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_get",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "294367607555203296491395321404569894747",
            "length": 326.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-93667ad5",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_unregister_dev",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "38777979769709700142436650796305740622",
            "length": 993.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-9e2ae8b3",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_reset",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "278928399992180678510816322500386894448",
            "length": 418.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-a5f07108",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_get",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "294367607555203296491395321404569894747",
            "length": 326.0
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-ad543921",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "include/net/bluetooth/hci_core.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "106196184799633052284294279222813282009",
                "275056385033110411830936956058217273675",
                "259942651842730034887740296301704717149",
                "259662397359439776566559537067476372769",
                "59520468866835026619420159718565430065",
                "132066140372301669209636425670959248026",
                "70600800260332437768414148103471773342",
                "280740854900640219400918661551144112872"
            ]
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-c2c77b22",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "80129253253061740067487708030095149486",
                "263399525196561385669232865061010247743",
                "331625945996439791403563373854863959262",
                "20083222743231906119217925802603213539",
                "319814484023847758208038088701389051304",
                "28774360149078570907428716678912736699",
                "316044724746173805471656069261766804838",
                "175984556566257590969819529720512806523",
                "181789517818256255783256910958794831418",
                "307538052428778242930682639395128684887",
                "220579718742990962498494136710049928108",
                "264990308291589138267027048244707339358",
                "292874667613018504835064712093903147810",
                "225998145572502031619934384776436925536",
                "90376410453211397509737514594637555940",
                "115809259333594453341921524337513220715",
                "90874657339490187821222965573850928396",
                "171039570356542300112428946160698160122",
                "191008653304398227820054449043798755510",
                "188276804667093766077218408479248089281",
                "178032849155355310892978702827690467034",
                "17066088356490712992059728026855063179",
                "85311724638334798139320755343995160881",
                "272914272454073212942862824222930754499",
                "212399008438049892395570948588703519196",
                "132453222626100081109911874558041729535"
            ]
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-da662cfa",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_unregister_dev",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "38777979769709700142436650796305740622",
            "length": 993.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-db4a68c8",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce23b73f0f27e2dbeb81734a79db710f05aa33c6",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_alloc_dev_priv",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "119359151509322460895433990163054008786",
            "length": 4197.0
        }
    },
    {
        "signature_type": "Function",
        "id": "CVE-2025-38250-e9be9dac",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bc0819a25e04cd68ef3568cfa51b63118fea39a7",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "hci_dev_reset",
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "function_hash": "278928399992180678510816322500386894448",
            "length": 418.0
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-f9a36fdf",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e5c144c557df910ab64d9c25d06399a9a735e65",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "include/net/bluetooth/hci_core.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "106196184799633052284294279222813282009",
                "275056385033110411830936956058217273675",
                "259942651842730034887740296301704717149",
                "259662397359439776566559537067476372769",
                "59520468866835026619420159718565430065",
                "132066140372301669209636425670959248026",
                "70600800260332437768414148103471773342",
                "280740854900640219400918661551144112872"
            ]
        }
    },
    {
        "signature_type": "Line",
        "id": "CVE-2025-38250-fb5403e4",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1d6123102e9fbedc8d25bf4731da6d513173e49e",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "net/bluetooth/hci_core.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "80129253253061740067487708030095149486",
                "263399525196561385669232865061010247743",
                "331625945996439791403563373854863959262",
                "20083222743231906119217925802603213539",
                "319814484023847758208038088701389051304",
                "28774360149078570907428716678912736699",
                "316044724746173805471656069261766804838",
                "175984556566257590969819529720512806523",
                "181789517818256255783256910958794831418",
                "307538052428778242930682639395128684887",
                "220579718742990962498494136710049928108",
                "264990308291589138267027048244707339358",
                "292874667613018504835064712093903147810",
                "225998145572502031619934384776436925536",
                "90376410453211397509737514594637555940",
                "115809259333594453341921524337513220715",
                "90874657339490187821222965573850928396",
                "171039570356542300112428946160698160122",
                "191008653304398227820054449043798755510",
                "188276804667093766077218408479248089281",
                "178032849155355310892978702827690467034",
                "17066088356490712992059728026855063179",
                "85311724638334798139320755343995160881",
                "272914272454073212942862824222930754499",
                "212399008438049892395570948588703519196",
                "132453222626100081109911874558041729535"
            ]
        }
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
6.6.97
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.36
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.5