CVE-2025-38304

Source
https://cve.org/CVERecord?id=CVE-2025-38304
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38304.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38304
Downstream
Related
Published
2025-07-10T07:42:15.466Z
Modified
2026-03-20T12:42:48.016821Z
Summary
Bluetooth: Fix NULL pointer deference on eir_get_service_data
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: Fix NULL pointer deference on eirgetservice_data

The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIRSERVICEDATA.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38304.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8f9ae5b3ae80f168a6224529e3787f4fb27f299a
Fixed
497c9d2d7d3983826bb02c10fb4a5818be6550fb
Fixed
4bf29910570666e668a60d953f8da78e95bb7fa2
Fixed
842f7c3154d5b25ca11753c02ee8cf6ee64c0142
Fixed
7d99cc0f8e6fa0f35570887899f178122a61d44e
Fixed
20a2aa01f5aeb6daad9aeaa7c33dd512c58d81eb

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38304.json"