CVE-2025-40282

Source
https://cve.org/CVERecord?id=CVE-2025-40282
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40282.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40282
Downstream
Related
Published
2025-12-06T21:51:06.287Z
Modified
2026-03-12T02:19:21.067079Z
Summary
Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: 6lowpan: reset link-local header on ipv6 recv path

Bluetooth 6lowpan.c netdev has headerops, so it must set link-local header for RX skb, otherwise things crash, eg. with AFPACKET SOCK_RAW

Add missing skbresetmac_header() for uncompressed ipv6 RX path.

For the compressed one, it is done in lowpanheaderdecompress().

Log: (BlueZ 6lowpan-tester Client Recv Raw - Success)

kernel BUG at net/core/skbuff.c:212! Call Trace: <IRQ> ... packetrcv (net/packet/afpacket.c:2152) ... <TASK> __localbhenableip (kernel/softirq.c:407) netifrx (net/core/dev.c:5648)

chanrecvcb (net/bluetooth/6lowpan.c:294 net/bluetooth/6lowpan.c:359)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40282.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
18722c247023035b9e2e2a08a887adec2a9a6e49
Fixed
ea46a1d217bc82e01cf3d0424e50ebfe251e34bf
Fixed
973e0271754c77db3e1b6b69adf2de85a79a4c8b
Fixed
d566e9a2bfc848941b091ffd5f4e12c4e889d818
Fixed
4ebb90c3c309e6375dc3e841af92e2a039843e62
Fixed
c24ac6cfe4f9a47180a65592c47e7a310d2f9d93
Fixed
11cd7e068381666f842ad41d1cc58eecd0c75237
Fixed
70d84e7c3a44b81020a3c3d650a64c63593405bd
Fixed
3b78f50918276ab28fb22eac9aa49401ac436a3b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40282.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
5.4.302
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.247
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.59
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40282.json"