We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38315

Bluetooth: btintel: Check dsbr size from EFI variable



Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct btintel_dsbr is already known, we can just start there instead of querying the EFI variable size. If the final result doesn't match what we expect also fail. This fixes a stack buffer overflow when the EFI variable is larger than struct btintel_dsbr.

Reserved 2025-04-16 | Published 2025-07-10 | Updated 2025-07-10 | Assigner Linux

Product status

Default status
unaffected

eb9e749c0182affafadfbe5ded4503c4b5a9b57c before 9427f6081f37c795a8bd29d0ee72a4da3bd64af8
affected

eb9e749c0182affafadfbe5ded4503c4b5a9b57c before 7b8526bb489780ccc0caffc446ecabec83cfe568
affected

eb9e749c0182affafadfbe5ded4503c4b5a9b57c before 3aa1dc3c9060e335e82e9c182bf3d1db29220b1b
affected

Default status
affected

6.11
affected

Any version before 6.11
unaffected

6.12.34
unaffected

6.15.3
unaffected

6.16-rc1
unaffected

References

git.kernel.org/...c/9427f6081f37c795a8bd29d0ee72a4da3bd64af8

git.kernel.org/...c/7b8526bb489780ccc0caffc446ecabec83cfe568

git.kernel.org/...c/3aa1dc3c9060e335e82e9c182bf3d1db29220b1b

cve.org (CVE-2025-38315)

nvd.nist.gov (CVE-2025-38315)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38315

Support options

Helpdesk Chat, Email, Knowledgebase