CVE-2025-40141

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-40141
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40141.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40141
Downstream
Published
2025-11-12T10:23:24.856Z
Modified
2025-11-27T02:33:09.851908Z
Summary
Bluetooth: ISO: Fix possible UAF on iso_conn_free
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: Fix possible UAF on isoconnfree

This attempt to fix similar issue to scoconnfree where if the conn->sk is not set to NULL may lead to UAF on isoconnfree.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/40xxx/CVE-2025-40141.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Fixed
eba6d787ec117a5d2c60f9644e0a39c18542b6be
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Fixed
5319145a07d8bf5b0782b25cb3115825689d42bb
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Fixed
80689777919f02328eb873769de4647c9dd3e371
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Fixed
c92ad1a155ccfa38b87bd1d998287e1c0a24248d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccf74f2390d60a2f9a75ef496d2564abb478f46a
Fixed
9950f095d6c875dbe0c9ebfcf972ec88fdf26fc8

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.156
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.112
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.53
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.3